Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

1.

...

  • Current 'mode' for verifying peer certificate is a global option, it's good to have specific mode among different sites hosted on a same machine. If the mode is non-empty, it would be the preference when making the decision to verify peer or not. Otherwise, the global mode will take effect.
    Code Block
    
       # Client certification level should be:
       # 0 no client certificates
       # 1 client certificates optional
       # 2 client certificates required
       CONFIG proxy.config.ssl.client.certification_level INT 0
    

2. Optimization on TLS record size

...

SSL

...

...

3. Configurable session time

  • Session size is configurable, whereas application can not specify a session time out threshold. The default is 300 seconds. In some cases, applications need to reduce or increase the caching time, it's good to be configurable.

4. Expose API to extract peer certificate data

...

_read size threshold

  • A few customers expect a size threshold for client request over ssl from protecting system perspective. If the max requested data exceed the threshold, server will reject the client connection

    .