openresty / openresty/lua-nginx-module
Will lua tcpsocksslhandshake be able to support mtls?
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 11.8k
- Forks
- 2.1k
- Avg merge
- 6h 1m
- Merged PRs (30d)
- 6
Description
https://github.com/openresty/lua-nginx-module#tcpsocksslhandshake
Refers to enabling the tcp client being able to validate or ignore TLS validation with a truststore via:
https://github.com/openresty/lua-nginx-module#lua_ssl_trusted_certificate
https://github.com/openresty/lua-nginx-module#lua_ssl_verify_depth
Is there any roadmap or potential to also support enabling the client to pass its public certificate to support mutual authentication?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the tcpsocksslhandshake documentation and the linked lua_ssl_trusted_certificate and lua_ssl_verify_depth settings. The issue does not name an implementation file or test; clarify the client certificate and key configuration needed for mutual TLS, then define the affected API and acceptance criteria.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- lua
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100