3 ms·
It's also not very developer/ops friendly. Quite hard to set up currently. Not that this couldn't be fixed (as the client side), but no one is doing this.
by tex0 10y ago
It's also not very developer/ops friendly. Quite hard to set up currently.
Not that this couldn't be fixed (as the client side), but no one is doing this.
- drdaeman 10y agoCan you elaborate please? A simplest form (equivalent of basic auth, but secure) is mere "ssl_client_certificates file.pem; ssl_verify_client on;" or equivalent - one just have to tell "ask for certificate" and "here are my trusted issuers". I guess, the only thing that's probably lacking is pluggable modules for popular web frameworks (issuing certs and matching them to users in DB).