Release of nginx 1.23.4 with TLSv1.3 enabled by default

The release of the main branch nginx 1.23.4 has been formed, which continues the development of new features. The parallel stable branch 1.22.x only receives changes related to the elimination of serious bugs and vulnerabilities. In the future, a stable branch 1.24 will be formed based on the main branch 1.23.x.

Among the changes:

  • The TLSv1.3 protocol is enabled by default.
  • A warning will be issued if there is a override of the protocol settings for the listening socket.
  • When the client uses 'pipelining' mode, connections are closed while waiting for additional data (lingering close).
  • The ngx_http_gzip_static_module now supports byte ranges.
  • The logging level for 'crit' has been changed to 'info' SSL-errors 'data length too long', 'length too short', 'bad legacy version', 'no shared signature algorithms', 'bad digest length', 'missing sigalgs extension', 'encrypted length too long', 'bad length', 'bad key update', 'mixed handshake and non-handshake data', 'ccs received early', 'data between ccs and finished', 'packet length too long', 'too many warn alerts', 'record too small' and 'got a fin before a ccs'.
  • Support for port ranges has been established in the listen directive.
  • The issue with selecting the incorrect location block when using a prefix location longer than 255 characters has been resolved.
  • Support for non-ASCII characters in file names on Windows has been added in the ngx_http_autoindex_module and ngx_http_dav_module, as well as in the include directive.
  • A socket leak has been fixed when using HTTP/2 and the error_page directive for redirecting errors with code 400.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster