Vos remboursements

2015-12-04 Thread Votre Assurance Maladie

Re: SEGFAULT in in buffer_insert_line2

2015-12-04 Thread Willy Tarreau
On Fri, Dec 04, 2015 at 09:18:38AM +0100, Bernd Helm wrote: > On 12/03/2015 06:53 PM, Willy Tarreau wrote: > >Maybe we're facing a bug where the buffer wraps at the end or something > >like this. Bernd, if you still have the core, could you please issue > >"print *b" while in buffer_insert_line2()

Re: SSL handshake failure when using "send-proxy" on HTTPS backend

2015-12-04 Thread Jonathan Leroy - Inikup
Hi, 2015-12-04 17:02 GMT+01:00 Lukas Tribus : > Well, you will have to update the first config line in nginx: > set_real_ip_from fc00::/7 > > To allow proxy connection from the ULA range. Already done. > As to the original problem: > I don't think you can use both SSL and non-SSL on the same po

Re: HAProxy setup

2015-12-04 Thread Bryan Talbot
On Fri, Dec 4, 2015 at 5:16 AM, Milos Zupancic wrote: > Hi, > > I am looking for a solution on how to setup HaProxy and Tomcat with SSL > termination + passing client certificate to the backend tomcat. > > > backend c-https > mode http > balance roundrobin > cookie SERVERI

Re: Contribution for HAProxy: Peer Cipher based SSL CTX switching

2015-12-04 Thread Bryan Talbot
On Fri, Dec 4, 2015 at 6:15 AM, Dave Zhu (yanbzhu) wrote: > Hey Bryan, > it’s strange that it’s always loading the ECC cert. I just tested the code > on my end and I’m not seeing this behavior. > > I see it on OSX, I'll test on Linux today. > Back to your original problem though, do the certs

RE: SSL handshake failure when using "send-proxy" on HTTPS backend

2015-12-04 Thread Lukas Tribus
> 2015-12-04 16:27 GMT+01:00 Jonathan Leroy - Inikup : >> Hi Luke, >> >> Here's the Nginx config : >> https://gist.githubusercontent.com/jleroy/ab45c328263731c46ec1/raw/69af9edc154329c113aad588ff5f9501edfd61b1/gistfile1.txt > > Now that I use ULA instead of link-local addresses, send-proxy no > lon

Re: SSL handshake failure when using "send-proxy" on HTTPS backend

2015-12-04 Thread Jonathan Leroy - Inikup
2015-12-04 16:27 GMT+01:00 Jonathan Leroy - Inikup : > Hi Luke, > > Here's the Nginx config : > https://gist.githubusercontent.com/jleroy/ab45c328263731c46ec1/raw/69af9edc154329c113aad588ff5f9501edfd61b1/gistfile1.txt Now that I use ULA instead of link-local addresses, send-proxy no longer works o

Re: Error when using an IPv6 link-local address as backend

2015-12-04 Thread Jonathan Leroy - Inikup
2015-12-04 14:14 GMT+01:00 Lukas Tribus : > I would strongly suggest to avoid link-local addresses for any services > and applications. > > If you need to keep this off the internet, you better assign ULA prefixes > and use those. > > > Using link-local addresses is asking for trouble, imho. It wo

Re: SSL handshake failure when using "send-proxy" on HTTPS backend

2015-12-04 Thread Jonathan Leroy - Inikup
2015-12-04 13:23 GMT+01:00 Lukas Erlacher : > Please show the nginx config. Hi Luke, Here's the Nginx config : https://gist.githubusercontent.com/jleroy/ab45c328263731c46ec1/raw/69af9edc154329c113aad588ff5f9501edfd61b1/gistfile1.txt Thanks, -- Jonathan Leroy http://www.inikup.com/ Tel: +33 (0)

Re: HAProxy setup

2015-12-04 Thread Kobus Bensch
I had a similar challenge. What I elected to do was to termninate ssl on the HAproxy that then pass it to an apache. From there I have an AJP Port to a tomcat. So I LB the Apache not the tomcat. Tomcat only listens on ajp. HTH On 04/12/2015 13:16, Milos Zupancic wrote: Hi, I am looking for

Re: Contribution for HAProxy: Peer Cipher based SSL CTX switching

2015-12-04 Thread Dave Zhu (yanbzhu)
Hey Bryan, it's strange that it's always loading the ECC cert. I just tested the code on my end and I'm not seeing this behavior. Back to your original problem though, do the certs share a CN or SAN? That's the only way that they would get loaded together into a shared context. -Dave From: Bry

Re:NAHB International Builders' Show 2016

2015-12-04 Thread Charlotte Kate
Hello, Sorry to interrupt in between your daily schedules. This is just a quick follow up regarding the email I sent you yesterday. (Please see below) I would really appreciate if you can give me a short response (not more than one line) whether you are interested in the attendees' database

HAProxy setup

2015-12-04 Thread Milos Zupancic
Hi, I am looking for a solution on how to setup HaProxy and Tomcat with SSL termination + passing client certificate to the backend tomcat. At the moment we use Apache for SSL termination and proxy balancer to point to tomcat AJP port. Application on tomcat needs the client certificate in order t

RE: Error when using an IPv6 link-local address as backend

2015-12-04 Thread Lukas Tribus
> Hi, > > All my backend servers are connected to a private, IPv6-only network. > When I'm trying to use their addresses in "server" directive, HAProxy > fails to connect to them. I would strongly suggest to avoid link-local addresses for any services and applications. If you need to keep this of

Re: SSL handshake failure when using "send-proxy" on HTTPS backend

2015-12-04 Thread Lukas Erlacher
Please show the nginx config. Best, Luke On 12/04/2015 03:30 AM, Jonathan Leroy - Inikup wrote: Hi, I have two backends named "nginx-http" and "nginx-https": the first one handle HTTP connections, the second one HTTPS connections. The proxy protocol works successfully on nginx-http backend:

Vos coupons de réduction en restaurant

2015-12-04 Thread Léon de Bruxelles
Léon de Bruxelles Profitez de vos coupons : 10€ et 20€ de réduction immédiate* ! Si ce message ne s'affiche pas correctement, visualisez la version en ligne.

Jusqu'à 20 euros de reduction immédiate sur votre addition

2015-12-04 Thread Leon de Bruxelles
  [ 10€ et 20€ de réduction immédiate sur votre addition* ! ]( http://r.grandenouvelle.fr/2vdiyd9wtactsbd.html ) [ ]( http://r.grandenouvelle.fr/2vdiyd9xlqctsbd.html ) [ ]( http://r.grandenouvelle.fr/2vdiyd9ye6ctsbd.html ) [ ]( http://r.grandenouvelle.fr/2vdiyd9z6mctsbd.html ) [ ]( http://r

[SPAM] bicycle parts offer from Snow li

2015-12-04 Thread Snow li
Dear mr:THIS IS Snow,i'm from Lizhi  bike co.,ltd.First of all, very glad to receive your email, If you need the quotation about the bicycle parts, and kids bike. u can contact me, I will provide you with the most preferential price, so that you will be more than a reference price, f

Re: [SPAM] Visibility on tune.ssl.cachesize

2015-12-04 Thread Cyril Bonté
Hi Olivier, OT : do you have the hand on the ajeux.com DNS entries ? Can you provide a (valid) SPF record so that your mails won't be detected as spam anymore. I guess you may have some troubles outside of the mailing list too. Le 04/12/2015 08:19, Baptiste a écrit : On Wed, Dec 2, 2015 at

Re: Why does this config snippet fail

2015-12-04 Thread Cyril Bonté
Hi Andreas, Le 03/12/2015 12:23, Andreas Mock a écrit : Hi all, I'm using this snippet in the config of version 1.5.14 of haproxy: http-request redirect location https://www.domain.%[req.fhdr(accept-language),lower,language(de-at;de-ch,de),map(/etc/haproxy/language-map.txt,de)]/ code 301 As

Re: SEGFAULT in in buffer_insert_line2

2015-12-04 Thread Bernd Helm
On 12/03/2015 06:53 PM, Willy Tarreau wrote: Maybe we're facing a bug where the buffer wraps at the end or something like this. Bernd, if you still have the core, could you please issue "print *b" while in buffer_insert_line2() ? yes, i still have the core. (gdb) frame 1 #1 0x00413349