Index | Thread | Search

From:
Sören Tempel <soeren@soeren-tempel.net>
Subject:
Re: [PATCH] relayd client certificate validation again
To:
Theo Buehler <tb@theobuehler.org>
Cc:
tech@openbsd.org, markus.l2ll@gmail.com, rivo@elnit.ee, brian@planetunix.net
Date:
Mon, 28 Oct 2024 19:17:12 +0100

Download raw body.

Thread
Hi Theo,

Sorry to bother you again about this, but as far as I can tell the patch
hasn't been merged yet. Did you want me to send an updated patch with
the man page change? I thought that you would just change that on
commit. If there is anything else that needs doing, just let me know.

All the best
Sören

Sören Tempel <soeren@soeren-tempel.net> wrote:
> Hi Theo,
> 
> Thanks for taking the time to take another look at the patch!
> 
> > > diff --git usr.sbin/relayd/relayd.conf.5 usr.sbin/relayd/relayd.conf.5
> > > index 50c73cbec15..771d3632398 100644
> > > --- usr.sbin/relayd/relayd.conf.5
> > > +++ usr.sbin/relayd/relayd.conf.5
> > > @@ -954,6 +954,10 @@ will be used (strong crypto cipher suites without anonymous DH).
> > >  See the CIPHERS section of
> > >  .Xr openssl 1
> > >  for information about TLS cipher suites and preference lists.
> > > +.It Ic client ca Ar path
> > > +Require TLS client certificates whose authenticity can be verified
> > > +against the CA certificate(s) in the specified file in order to
> > > +proceed beyond the TLS handshake.
> > 
> > Maybe this could be simplified to
> > 
> > 	Require TLS client certificates that can be verified against the CA
> > 	certificates in the specified file.
> > 
> > Other than that the diff looks good to me and I think it should go in
> 
> Good catch, this seems better worded to me too.
> 
> Feel free to change it accordingly!
> 
> Sincerely
> Sören