mirror of
https://github.com/corda/corda.git
synced 2025-06-13 04:38:19 +00:00
Update ssl-termination.md
This commit is contained in:
@ -25,7 +25,7 @@ Design of the [float](../design.md) is critically influenced by the decision of
|
||||
|
||||
#### Disadvantages
|
||||
|
||||
1. May limit cryptography options to RSA, and prevent checking of X500 names (only the root certificate checked) - Corda certificates are not totally standard;
|
||||
1. May limit cryptography options to RSA, and prevent checking of X500 names (only the root certificate checked) - Corda certificates are not totally standard.
|
||||
2. Doesn’t allow identification of the message source.
|
||||
3. May require additional work and SASL support code to validate the ultimate origin of connections in the float.
|
||||
|
||||
@ -34,7 +34,7 @@ Design of the [float](../design.md) is critically influenced by the decision of
|
||||
##### Advantages
|
||||
|
||||
1. Maintain authentication support
|
||||
2. Can authenticate against keys held internallye.g. Legal Identity not just TLS
|
||||
2. Can authenticate against keys held internally e.g. Legal Identity not just TLS.
|
||||
|
||||
##### Disadvantages
|
||||
|
||||
@ -89,12 +89,12 @@ Design of the [float](../design.md) is critically influenced by the decision of
|
||||
|
||||
##### Disadvantages
|
||||
|
||||
1. Risks losing the TLS private key
|
||||
1. Risks losing the TLS private key.
|
||||
2. Probably not allowed.
|
||||
|
||||
## Recommendation and justification
|
||||
|
||||
Proceed with Variant option 1a: Terminate on firewall; include SASL connection checking
|
||||
Proceed with Variant option 1a: Terminate on firewall; include SASL connection checking.
|
||||
|
||||
|
||||
|
||||
|
Reference in New Issue
Block a user