4 ms·
> we were able to make some legacy apps use SSL/TLS without adding any code at all How did you deal with certificate validation?
by ekiwi 9y ago
> we were able to make some legacy apps use SSL/TLS without adding any code at all
How did you deal with certificate validation?
- Mister_Snuggles 9y agoThis[0] seems to answer your questions. TL;DR: The kernel does it all and passes the unencrypted traffic to the local port specified. There's a command to configure it with the appropriate keys, etc. [0] http://www.c0t0d0s0.org/archives/5575-Less-known-Solaris-Features-kssl.html http://www.c0t0d0s0.org/archives/5575-Less-known-Solaris-Fea...
- sannee 9y agoSounds like nginx streams - http://nginx.org/en/docs/stream/ngx_stream_core_module.html http://nginx.org/en/docs/stream/ngx_stream_core_module.html . Really useful if you need TLS but the author of whatever you are running couldn't be bothered by adding support (includes being able to do client certificate auth!).
- derefr 9y agoSo, the same API semantics as IPSec transport mode, but not using IPSec. Seems like the best of both worlds, really.
- blinkingled 9y agoWell the app didn't care - we had self signed certs (actually internal CA signed IIRC) that we had to feed to the kernel ssl module using the ksslconfig commands. Edit: @Mister_Snuggles points to a link below if you wanted to run through the whole process.