Re: Haproxy support for HTTPS (SSL) backend servers

2010-10-16 Thread Nicholas Hadaway

 ACL features work just fine in TCP mode as well as HTTP mode.

-nick

On 10/16/2010 3:34 AM, Pasi Kärkkäinen wrote:

Hello,

I'd like to use haproxy to loadbalance a service
that uses (only) https in the backend.. service in question
cannot be changed to provide http, it's https only.
(I know, it's stupid, but I cannot change that unfortunately..)

I know I could use the haproxy 'raw' mode, but I need some of the
ACL features of haproxy, so I need to use the http mode instead.

Does someone have a patch that allows using https on the backend?

If there's no such patch, how big changes it would require?
I might work on it if there's nothing ready yet..

Thanks!

-- Pasi







switching from nginx to stunnel

2010-06-18 Thread Nicholas Hadaway
Hi All,

stunnel 4.33 has been released, is there a new X-Forwarded-For
patch?


  Thanks,
Nick




Re: Throughput degradation after upgrading haproxy from 1.3.22 to 1.4.1

2010-03-22 Thread Nicholas Hadaway

Chunked encoding support...

http://github.com/agentzh/chunkin-nginx-module

-nick

On 3/22/2010 4:57 AM, Timh Bergström wrote:
The problem with nginx is that it doesnt support chunked-encoding. 
Since that is what we are after, we can't use nginx until it supports 
it or until we can get rid of chunked encoding. So posting about how 
good it is working for you is not really helping our issue. Thanks though.


BR,
Timh



2010/3/19 duncan hall dun...@viator.com mailto:dun...@viator.com

Throw me in a forth on this one.  I use nginx 0.8.34 for gzip
compression, RAM caching of static content and SSL offload. All
very simple to configure and low overheads.  All requests HTTP and
HTTPs go to Nginx and are then forwarded to HAproxy 1.4.2 as HTTP.
Regards,

Duncan



Harvey Yau wrote:

I can third this - nginx + haproxy works extremely well.  I
wish haproxy supported SSL directly.  I realize it's not
within the design goals of haproxy, but the need for this is
out there.  Good thing nginx + haproxy works well enough.

-- Harvey

On 3/18/10 3:29 PM, Nicholas Hadaway wrote:

I can second this comment and say that it works extremely
well...  nginx operates very nicely as an SSL offloading
device.

I am right now using nginx 0.8.33 (soon to bump up to
0.8.34) and HAProxy 1.4.2 in production and things work
very well for me.

-Nick


Maybe it's worth a try for you to get along with nginx
as stunnel
replacement ?
Its performance is quit good and the config can be
held very short,
too for only accepting ssl traffic
and directing it to haproxy.

kind regards,
Malte











--
Timh Bergström
System Operations Manager
Diino AB - www.diino.com http://www.diino.com
:wq