Re: ssl_reject_handshake disallow TLSv1.3

2022-02-08 Thread Jeffrey Walton
On Tue, Feb 8, 2022 at 8:02 AM Sergey Kandaurov wrote: > > > > On 8 Feb 2022, at 14:15, rjvbzeoibvpzie wrote: > > > > ssl_protocols TLSv1.2 TLSv1.3; > > > > server { > >listen 443 ssl default_server; > >ssl_reject_handshake on; > > } > > > > This does not allow ANY other server to be rea

Re: ssl_reject_handshake disallow TLSv1.3

2022-02-08 Thread Sergey Kandaurov
> On 8 Feb 2022, at 14:15, rjvbzeoibvpzie wrote: > > ssl_protocols TLSv1.2 TLSv1.3; > > server { >listen 443 ssl default_server; >ssl_reject_handshake on; > } > > This does not allow ANY other server to be reached with TLSv1.3 > [..] You didn't specify OpenSSL version, so I assume t

ssl_reject_handshake disallow TLSv1.3

2022-02-08 Thread rjvbzeoibvpzie
ssl_protocols TLSv1.2 TLSv1.3; server { listen 443 ssl default_server; ssl_reject_handshake on; } This does not allow ANY other server to be reached with TLSv1.3 server { listen 443 ssl default_server; ssl_certificate ssl/cert.pem; return 444; } This allow ANY server to be