Add verify_client_certificate.
- Vorherrschende Sprache
- C++
- Sterne
- 28.9k
- Forks
- 5.6k
- Ø Merge
- 1 T. 22 Std.
- Gemergte PRs (30 T.)
- 430
Beschreibung
From https://github.com/envoyproxy/envoy/pull/5207#issuecomment-447345279:
> I think that we could simply add `verify_client_certificate: true|check|false`, where:
> - `true` would verify the client certificate and reject connection if the verification failed (what we have today),
> - `check` would verify the client certificate, but forward it and the verification status via `x-forwarded-client-cert` or another header (for easier matching), regardless of the verification status,
> - `false` would forward the client certificate to the backend via `x-forwarded-client-cert` without attempting to verify it (to avoid crypto operations, do access control at the backend, etc.).
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.