Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Documentation: Missing certifacate options in SimpleClientCertAuth #204

Open
celestian opened this issue Jun 8, 2017 · 2 comments
Open

Comments

@celestian
Copy link
Contributor

It could be little confusing that we cannot see notes about how to tell Custodia which certificate we would like to use.

@tiran
Copy link
Member

tiran commented Jun 29, 2017

Custodia currently accepts all valid client certificate that are trusted by the CA (global option tls_cafile). There is no additional filtering or support for CRL or OCSP status checks.

IMO we should recommend Apache mod_ssl or other TLS terminates to perform these checks for us.

@simo5
Copy link
Member

simo5 commented Jun 29, 2017

+1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants