Ngemuva kwezinyanga ezi-5 zokuthuthuka, ukukhishwa okulungisayo kweseva ye-HTTP esebenza kahle kakhulu kanye neseva elibamba ye-nginx 1.20.2 enamaphrothokholi amaningi kulungiselelwe ngokuhambisana negatsha elizinzile elisekelwayo elingu-1.20.X, lapho izinguquko kuphela ezihlobene nokuqedwa kokubi kakhulu. amaphutha kanye nokuba sengozini kwenziwa.
Izinguquko eziyinhloko zengezwe phakathi nenqubo yokukhiqiza ukukhishwa okulungisayo:
- Ukuhambisana nomtapo wezincwadi we-OpenSSL 3.0 kuyaqinisekiswa.
- Kulungiswe iphutha ekubhaleni okuguquguqukayo kwe-SSL okungenalutho kulogi;
- Kulungiswe iphutha ekuvaleni ukuxhumana kwe-keepalive ngezingemuva ze-gRPC lapho ithola uhlaka lwe-GOAWAY;
- Ukubanda okungaguquki okwenzeke ngenkathi kwakhiwa uxhumano lwe-SSL kuma-backends kumojula yokusakaza;
- Ukulengiswa okungaguquki okwenzeke ngenkathi kwakhiwa uxhumano lwe-SSL nama-backend e-gRPC uma usebenzisa izindlela ezikhethiwe, zenhlolovo noma //dev/poll;
- Ukusetha okulungisiwe okuguquguqukayo kwe-$content_length uma usebenzisa umbhalo wekhodi wokudlulisa ohlutshiwe;
- Izicelo ezilungisiwe zilenga lapho usebenzisa i-HTTP/2 kanye nomyalelo we-aio_write.
Source: opennet.ru