Skip to content
Snippets Groups Projects
Commit 14297267 authored by ms217's avatar ms217
Browse files

trimmed the code since it seems to be enough to provide TLS 1.3 when Nginx was...

trimmed the code since it seems to be enough to provide TLS 1.3 when Nginx was linked against OpenSSL 1.1.1 at build time
parent 9fbc4aa0
No related branches found
No related tags found
1 merge request!1251Adds TLSv1.3 detection & support to Nginx
......@@ -1622,20 +1622,15 @@ class nginx_plugin {
$vhost_data['logging'] = $web_config['logging'];
// check if OpenSSL and Nginx supports TLS 1.3
$nginx_version = $app->system->getnginxversion(true);
$openssl_version = $app->system->getopensslversion(true);
$output = $app->system->exec_safe('nginx -V 2>&1');
if(preg_match('/built with OpenSSL\s*(\d+)(\.(\d+)(\.(\d+))*)?(\D|$)/i', $output[0], $matches)) {
$nginx_openssl_ver = $matches[1] . (isset($matches[3]) ? '.' . $matches[3] : '') . (isset($matches[5]) ? '.' . $matches[5] : '');
}
if(version_compare($app->system->getopensslversion(true), $nginx_openssl_ver, '>=')) {
if((version_compare($app->system->getnginxversion(true), '1.13.0', '>=') && version_compare($app->system->getopensslversion(true), '1.1.1', '>='))) {
$app->log('Enable TLS 1.3 for: '.$domain, LOGLEVEL_DEBUG);
$vhost_data['tls13_available'] = $app->system->getopensslversion(true);
}
if((version_compare($app->system->getnginxversion(true), '1.13.0', '>=') && version_compare($nginx_openssl_ver, '1.1.1', '>='))) {
$app->log('Enable TLS 1.3 for: '.$domain, LOGLEVEL_DEBUG);
$vhost_data['tls13_available'] = $nginx_openssl_ver;
}
$tpl->setVar($vhost_data);
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment