Re: AW: [users@httpd] Client certificate auth behind f5 loadbalancer

2014-06-28 Thread Marco Pizzoli
Hi Marc,
as F5 user maybe you are not yet aware that with F5, leveraging iRules, you
can:
- implement client cert verification/validation, also specifically checking
the CN of the certificate
- publish to the apache backend custom HTTP headers carrying informations
extracted from the client certificate

Both cases are well documented on the F5 site. The first one in particular
I can say by having implemented on my own.

Is it something useful to your case?

Regards
Marco




On Sat, Jun 28, 2014 at 5:04 PM, Marc Schöchlin  wrote:

> Hi,
>
> On 06/26/2014 04:08 PM, andre.wen...@bmw.de wrote:
> > Why do you terminate the ssl on the F5 and not on the Apache-backend? We
> load balance IP/Port-based on the F5 and terminate the SSL on the Apache
> backend, so you would be able to turn on your SSLEngine and Proxy the SSL
> from the F5 on the SSL Standard SSL Port 443 of the Apache and you can do
> everything you want because you have all SSL information.
>
> i use a wildcard certificate on my frontend ip to do irule-based (looking
> for the hostheader) backend pool selection.
> Therefore it would be good to terminate ssl in the f5.
>
> I will now use a new frontend ip on the loadbalancer and i then i will
> forward the traffic to the backend servers
>
> Regards
> Marc
>
> --
> GPG encryption available: 0x670DCBEC/pool.sks-keyservers.net
>
>
> -
> To unsubscribe, e-mail: users-unsubscr...@httpd.apache.org
> For additional commands, e-mail: users-h...@httpd.apache.org
>
>


Re: [users@httpd] Windows Apache 2.4.9 restarts itself

2014-06-28 Thread Jeff Trawick
On Fri, Jun 27, 2014 at 7:53 AM, Jeff Trawick  wrote:

> On Thu, Jun 26, 2014 at 4:18 AM, Mar Imp  wrote:
>
>> Hi,
>>
>> Thank you for the response!
>>
>> I looked into child.c, and see that the first line in Error log:
>> (OS 6)The handle is invalid.  : AH00356: Child: WAIT_FAILED --
>> shutting down server
>> comes from:
>> child.c Line 1125+: rv = WaitForMultipleObjects(num_events, (HANDLE
>> *)child_events, FALSE, ……
>> This is the place that causes the restart.
>>
>
> Right...  The other code I pointed out is what makes this call different
> than before.
>
>
>
>>
>> The second line in the error log:
>> (OS 10038)An operation was attempted on something that is not a
>> socket.  : AH00344: accept() failed.
>> comes from:
>> child.c Line 641+: if (context->accept_socket == INVALID_SOCKET)
>> I guess the second line in the error log is just a consequence of the
>> server shutting down?
>>
>
> I expect so.
>
>
>>
>>
>> no, I can’t build httpd. It would be great if you could provide a
>> patched version that I could install in _production_ environment.
>>
>> I can’t reproduce the error on a test server, I can just install the
>> version on a productive server, and wait for the error to occur. The
>> error occurs sporadically.
>>
>> It is essential that the patch included in the build doesn’t break
>> things (particularly the ability of apache to restart when an error
>> happens).
>>
>
> The Apache Lounge folks would need to run the build for you to ensure that
> it has any patches you're currently using and that the toolchain is in sync.
>
> Right now I hope to make some permanent changes in the next couple of days
> to improve diagnostics in this area and commit the changes to httpd trunk.
>  At that point you might be able to get the Apache Lounge folks to roll
> them into a special build.  ???
>
>
Here are the diagnostic changes I added:

http://svn.apache.org/viewvc?view=revision&revision=1606368

Perhaps the Apache Lounge folks can get you a build of 2.4.9 with that in
it.


>
>
>>
>> As you found out, I use the apachelounge-build atm.
>>
>> Thank you for your help!
>>
>> Kind regards
>> Maria Imp
>>
>> 2014-06-24 15:59 GMT+02:00 Jeff Trawick :
>> > On Tue, Jun 24, 2014 at 9:36 AM, Mar Imp  wrote:
>> >>
>> >> I face the problem, that Apache restarts itself unexpecteldy without
>> >> obvious reason.
>> >>
>> >> -> (OS 6)The handle is invalid.  : AH00356: Child: WAIT_FAILED --
>> >> shutting down server
>> >> -> (OS 10038)An operation was attempted on something that is not a
>> >> socket.  : AH00344: accept() failed.
>> >>
>> >> Apache Version:
>> >>   * Problem occurs on 2.4.9, both VC10 and VC11 compiled ones
>> >>   * Problem does NOT occur on 2.4.4
>> >> Operating System:
>> >>   * Microsoft Windows Server 2012 Standard
>> >>
>> >> The problem occurs since the Apache upgrade from 2.4.4 to 2.4.9.
>> >> At this moment I reverted to 2.4.4 again because the random restarts
>> >> cause downtimes.
>> >>
>> >>
>> >> Relevant configuration settings:
>> >> ThreadsPerChild 300
>> >> AcceptFilter http none
>> >> AcceptFilter https none
>> >> EnableSendfile off
>> >> EnableMMAP off
>> >>
>> >>
>> >> Apache works as a caching reverse proxy (mod_cache_disk)
>> >>
>> >>
>> >> Typical logfile fragment:
>> >> [log]
>> >> [Fri May 23 07:53:58.344457 2014] [mpm_winnt:crit] [pid 42540:tid 380]
>> >> (OS 6)The handle is invalid.  : AH00356: Child: WAIT_FAILED --
>> >> shutting down server
>> >> [Fri May 23 07:54:03.757607 2014] [mpm_winnt:warn] [pid 42540:tid
>> >> 4212] (OS 10038)An operation was attempted on something that is not a
>> >> socket.  : AH00344: accept() failed.
>> >> [Fri May 23 07:54:30.288807 2014] [mpm_winnt:notice] [pid 42540:tid
>> >> 380] AH00362: Child: Waiting 270 more seconds for 5 worker threads to
>> >> finish.
>> >> [Fri May 23 07:55:00.329552 2014] [mpm_winnt:notice] [pid 42540:tid
>> >> 380] AH00362: Child: Waiting 240 more seconds for 1 worker threads to
>> >> finish.
>> >> [Fri May 23 07:55:30.370221 2014] [mpm_winnt:notice] [pid 42540:tid
>> >> 380] AH00362: Child: Waiting 210 more seconds for 1 worker threads to
>> >> finish.
>> >> [Fri May 23 07:55:47.893020 2014] [mpm_winnt:notice] [pid 42540:tid
>> >> 380] AH00364: Child: All worker threads have exited.
>> >> [Fri May 23 07:55:48.010131 2014] [mpm_winnt:notice] [pid 36544:tid
>> >> 516] AH00428: Parent: child process 42540 exited with status 0 --
>> >> Restarting.
>> >> [Fri May 23 07:55:48.801890 2014] [mpm_winnt:notice] [pid 36544:tid
>> >> 516] AH00455: Apache/2.4.9 (Win64) OpenSSL/1.0.1g configured --
>> >> resuming normal operations
>> >> [Fri May 23 07:55:48.801890 2014] [mpm_winnt:notice] [pid 36544:tid
>> >> 516] AH00456: Apache Lounge VC10 Server built: Mar 17 2014 12:11:31
>> >> [Fri May 23 07:55:48.801890 2014] [core:notice] [pid 36544:tid 516]
>> >> AH00094: Command line: 'C:\\Apache24\\bin\\httpd.exe -d C:/Apache24'
>> >> [Fri May 23 07:55:48.802891 2014] [mpm_winnt:notice] [pid 36544:tid
>> >> 516] AH00418: Parent: Create

Re: AW: [users@httpd] Client certificate auth behind f5 loadbalancer

2014-06-28 Thread Marc Schöchlin
Hi,

On 06/26/2014 04:08 PM, andre.wen...@bmw.de wrote:
> Why do you terminate the ssl on the F5 and not on the Apache-backend? We load 
> balance IP/Port-based on the F5 and terminate the SSL on the Apache backend, 
> so you would be able to turn on your SSLEngine and Proxy the SSL from the F5 
> on the SSL Standard SSL Port 443 of the Apache and you can do everything you 
> want because you have all SSL information.

i use a wildcard certificate on my frontend ip to do irule-based (looking for 
the hostheader) backend pool selection.
Therefore it would be good to terminate ssl in the f5.

I will now use a new frontend ip on the loadbalancer and i then i will forward 
the traffic to the backend servers

Regards
Marc

-- 
GPG encryption available: 0x670DCBEC/pool.sks-keyservers.net


-
To unsubscribe, e-mail: users-unsubscr...@httpd.apache.org
For additional commands, e-mail: users-h...@httpd.apache.org