The original post: /r/nginx by /u/SirReal_SalvDali on 2025-02-14 16:15:00.

New to nginx… how are modules “signed”? I’m looking at a STIG (verbiage below) and can’t figure out how to verify this. I’m not a developer, just a security analyst checking their work.

Web Server SRG STIG Vuln ID : V-206373 “If… modules are put into production without being signed, this is a finding.”