Add post-quantum hybrid ECDHE-MLKEM for TLSv1.3 in our webserver #1886
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Related:
Pull Request:
service nginx status
tocurl -kfsSo/dev/null https://$INTERNETNL_DOMAINNAME --resolve $INTERNETNL_DOMAINNAME:443:127.0.0.1
ssl_ecdh_curve SecP384r1MLKEM1024:X25519MLKEM768:SecP256r1MLKEM768:...
Result:
openssl s_client -connect 127.0.0.1:443 -servername internet.test -groups X25519MLKEM768 |grep group
Update: there seems to be a bug regarding fetching the wrong env logs, now that is solved I suspect the health-check is not working because of authentication. There are multiple solutions:
ps -ef | grep nginx
netstat -a | grep 443
curl https://$INTERNETNL_DOMAINNAME/.well-known/security.txt
-f
flagPicked nr. 5 one, since it's actually the most 'full' test, with
-f
it was actually not just testing the webserver health, but also the app container (which is wrong, since restarting the webserver won't solve any app container issues).