1
Humorce 2019-09-21 21:42:40 +08:00 1
ssl_certificate : fullchain cert
ssl_trusted_certificate : ca cert |
3
Humorce 2019-09-21 22:20:13 +08:00
|
4
Humorce 2019-09-21 22:22:18 +08:00
@seers #2
具体如下: Syntax: ssl_trusted_certificate file; Default: — Context: http, server This directive appeared in version 1.3.7. Specifies a file with trusted CA certificates in the PEM format used to verify client certificates and OCSP responses if ssl_stapling is enabled. |
5
msg7086 2019-09-22 00:51:11 +08:00 via Android
trusted certificate 本来就是可信 ca 证书。这个证书必须是客户证书的上级,既然是上级,当然是 ca。fullchain 并没有什么用,因为 ca 的 ca 又不关认证。
|