关于修复Node.js应用(含Docker部署的Nuxt应用)中CVE-2021-38628漏洞:禁用TLSv1.0协议及验证方法的技术问询
Got it, let's walk through exactly how to disable TLSv1.0 for Node.js applications (including Dockerized Nuxt apps, which follow the same core principles as other Node.js web apps) and confirm the fix is working.
1. Plain Node.js HTTPS Servers
If you're running a raw Node.js HTTPS server, you can explicitly block TLSv1.0 by setting the secureOptions flag in your server configuration. Here's a concrete code example:
const https = require('https'); const fs = require('fs'); const constants = require('constants'); const sslOptions = { key: fs.readFileSync('path/to/your-private-key.pem'), cert: fs.readFileSync('path/to/your-certificate.pem'), // Disable TLSv1.0 entirely secureOptions: constants.SSL_OP_NO_TLSv1 }; https.createServer(sslOptions, (req, res) => { res.writeHead(200); res.end('Secure connection established!\n'); }).listen(443);
You can add constants.SSL_OP_NO_TLSv1_1 to the secureOptions value if you also want to disable TLSv1.1, leaving only the more secure TLSv1.2 and TLSv1.3 protocols enabled.
2. Nuxt.js Applications (Non-Docker)
Nuxt 2
Update your nuxt.config.js to include TLS restrictions in the server's HTTPS settings:
export default { server: { https: { key: fs.readFileSync('path/to/private-key.pem'), cert: fs.readFileSync('path/to/certificate.pem'), secureOptions: require('constants').SSL_OP_NO_TLSv1 } } };
Nuxt 3
For Nuxt 3, adjust your nuxt.config.ts (or .js) similarly:
import { defineNuxtConfig } from 'nuxt'; import constants from 'constants'; import fs from 'fs'; export default defineNuxtConfig({ server: { https: { key: fs.readFileSync('path/to/private-key.pem'), cert: fs.readFileSync('path/to/certificate.pem'), secureOptions: constants.SSL_OP_NO_TLSv1 } } });
3. Dockerized Nuxt Applications
Most Dockerized Nuxt setups use a reverse proxy like Nginx for SSL termination (this is the recommended approach over letting Nuxt handle SSL directly). Here's how to configure both common scenarios:
Scenario A: Nginx as SSL Termination Proxy
Edit your Nginx configuration file (mounted into the Docker container) to restrict allowed TLS protocols:
server { listen 443 ssl; server_name your-domain.com; ssl_certificate /path/to/certificate.pem; ssl_certificate_key /path/to/private-key.pem; # Allow only TLSv1.2 and TLSv1.3 ssl_protocols TLSv1.2 TLSv1.3; # Optional: Enforce strong cipher suites ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384; location / { proxy_pass http://nuxt-container:3000; # Point to your Nuxt service proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } }
After updating the config, restart your Nginx container to apply the changes.
Scenario B: Nuxt Handles SSL Directly in Docker
If you're keeping SSL handling inside the Nuxt container, ensure your nuxt.config.js/ts includes the secureOptions setting from the non-Docker section above. Then rebuild your Docker image and redeploy the container.
You can confirm the fix using the OpenSSL command you referenced:
openssl s_client -connect your-server-ip:port -tls1
- Successfully disabled: The command will fail with an error like
sslv3 alert handshake failure, meaning the server rejected the TLSv1.0 connection attempt. - Still enabled: The command will establish a connection and display SSL certificate details, indicating TLSv1.0 is still supported.
For a more comprehensive check, use nmap to list all active protocols:
nmap --script ssl-enum-ciphers -p your-port your-server-ip
This output will show all TLS versions the server accepts—verify that TLSv1.0 is not listed.
内容的提问来源于stack exchange,提问作者kuollam

