Joerg, Sorry for late reply, yes your solution is very correct.
mic 2012/2/8 Joerg Poeltl <joerg.poe...@newmind.at>: > thank you for the fast reply. > > I'm using scgi, so my setup looks like this: > > > location / { > include /etc/nginx/scgi_params; > scgi_pass 127.0.0.1:4000; > } > > to solve the problem I created a file "scgi_ssl_params" with following > content: > > scgi_param SSL_PROTOCOL $ssl_protocol; > scgi_param HTTPS on; > scgi_param SSL_CIPHER $ssl_cipher; > scgi_param SSL_CLIENT_SERIAL $ssl_client_serial; > scgi_param SSL_CLIENT_S_DN $ssl_client_s_dn; > scgi_param SSL_CLIENT_I_DN $ssl_client_i_dn; > scgi_param SSL_SESSION_ID $ssl_session_id; > scgi_param SSL_CLIENT_CERT $ssl_client_cert; > scgi_param SSL_CLIENT_RAW_CERT $ssl_client_raw_cert; > scgi_param SSL_CLIENT_VERIFY $ssl_client_verify; > > > and modified my setup to: > location / { > include /etc/nginx/scgi_params; > include /etc/nginx/scgi_ssl_params; > scgi_pass 127.0.0.1:4000; > } > >