Answer the question
In order to leave comments, you need to log in
How to configure nginx to block access to a resource if the certificate is spoofed?
There is a resource, access is configured only via https.
There is a client that has a third-party trusted root certificate installed. During the connection, the connection is established not with the server's certificate, but with a certificate signed by this root certificate. With the current settings, the browser is silent.
How to configure nginx so that when such a certificate substitution occurs on the client side, the server blocks access?
Purpose: Complete blocking of the ability to use the resource if a third-party certificate is used.
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question