mlibbey commented on pull request #7598:
URL: https://github.com/apache/trafficserver/pull/7598#issuecomment-799018654


   FWIW, our org uses a field inside the Subject DN eg, when connecting to the 
ATS with SNI cdn.example.com, only accept mTLS requests with Subject DN field 
containing the UID=ourorg.group.123, and with specific Issuer DN values. The 
security peeps also suggest/mandate/whatever that the cert should chain to 
specific roots. Even if this functionality doesn't make it into this version, 
might be nice to think through the config language to be able to add it later.


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[email protected]


Reply via email to