Fixes: https://tracker.ceph.com/issues/68310
Signed-off-by: Redouane Kachach <rkachach@ibm.com>
server {
+ ssl_client_certificate /etc/nginx/ssl/ca.crt;
+ ssl_verify_client on;
+
listen {{ internal_port }} ssl;
listen [::]:{{ internal_port }} ssl;
ssl_certificate /etc/nginx/ssl/nginx_internal.crt;
}"""),
"nginx_internal_server.conf": dedent("""
server {
+ ssl_client_certificate /etc/nginx/ssl/ca.crt;
+ ssl_verify_client on;
+
listen 29443 ssl;
listen [::]:29443 ssl;
ssl_certificate /etc/nginx/ssl/nginx_internal.crt;
}"""),
"nginx_internal_server.conf": dedent("""
server {
+ ssl_client_certificate /etc/nginx/ssl/ca.crt;
+ ssl_verify_client on;
+
listen 29443 ssl;
listen [::]:29443 ssl;
ssl_certificate /etc/nginx/ssl/nginx_internal.crt;