zoukankan      html  css  js  c++  java
  • haproxy ssl相关配置

    ssl-default-bind-options [<option>]...
      This setting is only available when support for OpenSSL was built in. It sets
      default ssl-options to force on all "bind" lines. Please check the "bind"
      keyword to see available options.
    
      Example:
            global
               ssl-default-bind-options no-sslv3 no-tls-tickets
    		   
    		   
    ssl-default-bind-options	
    
    
    这个设置是只可用的当支持OpenSSL ,它设置  default ssl-options  为force 在所有的bind 项,
    
    请检查 bind 关键字 来查看可用的选项:
      Example:
            global
               ssl-default-bind-options no-sslv3 no-tls-tickets
    		   
    force-sslv3
      This option enforces use of SSLv3 only on SSL connections instantiated from
      this listener. SSLv3 is generally less expensive than the TLS counterparts
      for high connection rates. This option is also available on global statement
      "ssl-default-bind-options". See also "no-tlsv*" and "no-sslv3".
    
    force-tlsv10
      This option enforces use of TLSv1.0 only on SSL connections instantiated from
      this listener. This option is also available on global statement
      "ssl-default-bind-options". See also "no-tlsv*" and "no-sslv3".
    
    force-tlsv11
      This option enforces use of TLSv1.1 only on SSL connections instantiated from
      this listener. This option is also available on global statement
      "ssl-default-bind-options". See also "no-tlsv*", and "no-sslv3".
    
    force-tlsv12
      This option enforces use of TLSv1.2 only on SSL connections instantiated from
      this listener. This option is also available on global statement
      "ssl-default-bind-options". See also "no-tlsv*", and "no-sslv3".
      
      
      no-sslv3
      This option disables support for SSLv3 when SSL is used to communicate with
      the server. Note that SSLv2 is disabled in the code and cannot be enabled
      using any configuration option. See also "force-sslv3", "force-tlsv*".
    
      Supported in default-server: No
      
      
      no-sslv3 
      
      这个选项 关闭支持SSLV3 当SSL是用于和server通讯,
      
    注意SSLv2 是在代码里关闭,不能使用任何配置选项来启用
    
    
      
      

  • 相关阅读:
    科学-化学:化学百科
    科学-物理:物理学 (自然科学学科)百科
    科学-建筑学-建筑美学:建筑美学百科
    科学-建筑学:建筑学百科
    科学-哲学-美学:美学(中国哲学二级学科)
    哲学:哲学(世界观学说、社会形态之一)
    科学-语文:语文(语言和文学的简称)
    科学-分析:分析
    建模:数学建模
    科学-数学:数学
  • 原文地址:https://www.cnblogs.com/zhaoyangjian724/p/6200349.html
Copyright © 2011-2022 走看看