You are viewing a plain text version of this content. The canonical link for it is here.
Posted to github@trafficserver.apache.org by GitBox <gi...@apache.org> on 2021/03/15 00:48:34 UTC

[GitHub] [trafficserver] mlibbey commented on pull request #7598: Add client_allow_list.so experimental plugin.

mlibbey commented on pull request #7598:
URL: https://github.com/apache/trafficserver/pull/7598#issuecomment-799018654


   FWIW, our org uses a field inside the Subject DN eg, when connecting to the ATS with SNI cdn.example.com, only accept mTLS requests with Subject DN field containing the UID=ourorg.group.123, and with specific Issuer DN values. The security peeps also suggest/mandate/whatever that the cert should chain to specific roots. Even if this functionality doesn't make it into this version, might be nice to think through the config language to be able to add it later.


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org