mirror of
https://github.com/corda/corda.git
synced 2025-01-01 02:36:44 +00:00
Update ssl-termination.md
This commit is contained in:
parent
1636a4bb0c
commit
f15f57e83d
@ -25,7 +25,7 @@ Design of the [float](../design.md) is critically influenced by the decision of
|
|||||||
|
|
||||||
#### Disadvantages
|
#### Disadvantages
|
||||||
|
|
||||||
1. May limit cryptography options to RSA, and prevent checking of X500 names (only the root certificate checked) - Corda certificates are not totally standard;
|
1. May limit cryptography options to RSA, and prevent checking of X500 names (only the root certificate checked) - Corda certificates are not totally standard.
|
||||||
2. Doesn’t allow identification of the message source.
|
2. Doesn’t allow identification of the message source.
|
||||||
3. May require additional work and SASL support code to validate the ultimate origin of connections in the float.
|
3. May require additional work and SASL support code to validate the ultimate origin of connections in the float.
|
||||||
|
|
||||||
@ -34,7 +34,7 @@ Design of the [float](../design.md) is critically influenced by the decision of
|
|||||||
##### Advantages
|
##### Advantages
|
||||||
|
|
||||||
1. Maintain authentication support
|
1. Maintain authentication support
|
||||||
2. Can authenticate against keys held internallye.g. Legal Identity not just TLS
|
2. Can authenticate against keys held internally e.g. Legal Identity not just TLS.
|
||||||
|
|
||||||
##### Disadvantages
|
##### Disadvantages
|
||||||
|
|
||||||
@ -89,12 +89,12 @@ Design of the [float](../design.md) is critically influenced by the decision of
|
|||||||
|
|
||||||
##### Disadvantages
|
##### Disadvantages
|
||||||
|
|
||||||
1. Risks losing the TLS private key
|
1. Risks losing the TLS private key.
|
||||||
2. Probably not allowed.
|
2. Probably not allowed.
|
||||||
|
|
||||||
## Recommendation and justification
|
## Recommendation and justification
|
||||||
|
|
||||||
Proceed with Variant option 1a: Terminate on firewall; include SASL connection checking
|
Proceed with Variant option 1a: Terminate on firewall; include SASL connection checking.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user