Disable only Hostname verification of proxied HTTPS server certificate

2019-11-07 Thread shivramg94
Is there any way where we can configure nginx to only verify the root of the proxied HTTPS server (upstream server) certificate and to skip the host name (or domain name) verification? As I understand, proxy_ssl_verify directive can be used to completely enable/disable the verification of proxied

Re: SSL handshake attack mitigation

2019-11-07 Thread Sergey Kandaurov
> On 6 Nov 2019, at 22:41, mogwai wrote: > > My first question is regarding the particular error log messages produced > during the attack - see example below: > > [info] 8050#8050: *146 SSL_do_handshake() failed (SSL: error:14094416:SSL > routines:ssl3_read_bytes:sslv3 alert certificate unkno