No Image

NGINX Updates Mitigate the August 2019 HTTP/2 Vulnerabilities

2019-08-14 KENNETH 0

NGINX Updates Mitigate the August 2019 HTTP/2 Vulnerabilities Today we are releasing updates to NGINX Open Source and NGINX Plus in response to the vulnerabilities recently discovered in the HTTP/2 protocol. We strongly recommend upgrading all systems that have HTTP/2 enabled. In May 2019, researchers at Netflix discovered a number of security vulnerabilities in several HTTP/2 server implementations. These were responsibly reported to each of the vendors and maintainers concerned. NGINX was vulnerable to three attack vectors, as detailed in the following CVEs: CVE-2019-9511 (Data dribble) CVE-2019-9513 (Resource loop) CVE-2019-9516 (Zero‑length headers leak) We have addressed these vulnerabilities, and added other HTTP/2 security safeguards, in the following NGINX versions: NGINX 1.16.1 (stable) NGINX 1.17.3 (mainline) NGINX Plus R18 P1 The post NGINX Updates Mitigate the August 2019 HTTP/2 Vulnerabilities appeared first on NGINX. Source: NGINX Updates Mitigate the August 2019 HTTP/2 Vulnerabilities

Using the NGINX Plus Ingress Controller for Kubernetes with OpenID Connect Authentication from Azure AD

2019-07-26 KENNETH 0

Using the NGINX Plus Ingress Controller for Kubernetes with OpenID Connect Authentication from Azure AD table.nginx-blog, table.nginx-blog th, table.nginx-blog td { border: 2px solid black; border-collapse: collapse; } table.nginx-blog { width: 100%; } table.nginx-blog th { background-color: #d3d3d3; align: left; padding-left: 5px; padding-right: 5px; padding-bottom: 2px; padding-top: 2px; line-height: 120%; } table.nginx-blog td { padding-left: 5px; padding-right: 5px; padding-bottom: 2px; padding-top: 5px; line-height: 120%; } table.nginx-blog td.center { text-align: center; padding-bottom: 2px; padding-top: 5px; line-height: 120%; } NGINX Open Source is already the default Ingress resource for Kubernetes, but NGINX Plus provides additional enterprise‑grade capabilities, including JWT validation, session persistence, and a large set of metrics. In this blog we show how to use NGINX Plus to perform OpenID Connect (OIDC) authentication for applications and resources behind the Ingress in a Kubernetes environment, in a setup that simplifies scaled rollouts. The following graphic [ more… ]

Culture@NGINX

2019-07-09 KENNETH 0

Culture@NGINX In our Life@NGINX post, we answer the question “what is life like at NGINX?”. In this post, we want to expand on a related topic: company culture. Senior Vice President and General Manager of NGINX at F5, Gus Robertson, recently noted how compatible the NGINX and F5 cultures are. In this post, we want to expand on why we think the NGINX culture within F5 is so special. Culture Is Key to Sustaining Success Company culture is a popular topic in today’s headlines, and an important one considering the number of hours each of us spends at work. But what is company culture, and more importantly, what is NGINX’s culture? When we talk about our culture, we consider how our values affect the past, present, and future of our employees, our products, and our customers. We remember that our experiences [ more… ]

Life@NGINX

2019-07-09 KENNETH 0

Life@NGINX One of the questions we hear most often from prospective employees is “what’s life like at NGINX?”. The answer is simple: we blend a tight-knit group of teams and colleagues who share a start‑up heritage and culture with the global support and benefits that come with being part of F5. In this blog post, we’ll look at life at NGINX in our global offices. NGINX Around the World Life at NGINX is diverse. The NGINX business unit at F5 has office locations internationally – in San Francisco, Cork, Singapore, Sydney, and Tokyo – not to mention our remote colleagues living and working in various places around the globe. While our team is scattered geographically, our culture is something that keeps us together as a community and makes Life at NGINX, and within the broader F5 family, what it is. Our culture is [ more… ]

No Image

Catching Up with the NGINX Application Platform: What’s New in 2019

2019-07-03 KENNETH 0

Catching Up with the NGINX Application Platform: What’s New in 2019 table.nginx-blog, table.nginx-blog th, table.nginx-blog td { border: 2px solid black; border-collapse: collapse; } table.nginx-blog { width: 100%; } table.nginx-blog th { background-color: #d3d3d3; align: left; padding-left: 5px; padding-right: 5px; padding-bottom: 2px; padding-top: 2px; line-height: 120%; } table.nginx-blog td { padding-left: 5px; padding-right: 5px; padding-bottom: 2px; padding-top: 5px; line-height: 120%; } table.nginx-blog td.center { text-align: center; padding-bottom: 2px; padding-top: 5px; line-height: 120%; } More than ever before, enterprises are recognizing that digital transformation is critical to their survival. In fact, the Wall Street Journal reports that executives currently see legacy operations and infrastructure as the #1 risk factor jeopardizing their ability to compete with companies that are “born digital”. Cloud, DevOps, and microservices are key technologies that accelerate digital transformation initiatives. And they’re paying off at companies that leverage them – [ more… ]