Category: Security

  • How Config Safety Protects NGINX Ingress Controller from Invalid Configuration

    How Config Safety Protects NGINX Ingress Controller from Invalid Configuration

    —

    by

    in ,

    NGINX Ingress Controller turns Kubernetes resources into NGINX configuration. Many of those inputs are free-form text: snippet annotations on Ingresses, snippets on VirtualServers, and in the global ConfigMap. A typo in any of them can produce configuration that NGINX refuses to load. Config safety makes sure such a mistake stays with the resource that introduced it. Configuration…

  • Encrypted Client Hello Comes to NGINX

    Encrypted Client Hello Comes to NGINX

    —

    by

    in

    Encrypted Client Hello (ECH) support in NGINX open source was contributed by Stephen Farrell, Computer Science Research Fellow, Trinity College Dublin (GitHub PR #840). This work was funded by the Open Technology Fund as part of the DEfO (Developing ECH for OpenSSL) project, which develops privacy-enhancing ECH implementations for OpenSSL and various web servers to…

  • Post-Quantum Cryptography (PQC) support in NGINX 

    Post-Quantum Cryptography (PQC) support in NGINX 

    —

    by

    in

    TL; DR: Not all Linux distros can run NGINX with PQC support. Read this article to learn which ones do, and how to do it yourself. At DEF CON 33, Konstantinos Karagiannis argued that usable quantum capabilities could arrive much sooner than many expect. Regardless of the exact date, agencies such as NIST, NSA, and…