Re: [PATCH] BUG/MEDIUM: stats: stats bind-process doesn't propagate the process mask correctly

2016-02-23 Thread Willy Tarreau
On Wed, Feb 24, 2016 at 12:14:54AM +0100, Cyril Bonté wrote: > The patch must be applied to 1.7, 1.6 and 1.5 Applied to 1.7 for now, will backport soon. Thanks Cyril! Willy

acl's re-calculated after reqrep ?

2016-02-23 Thread Jim Freeman
[ using 1.6.3 on Debian8 ] Are acl's re-calculated after a 'reqrep' of the request line? I'm seeing evidenced that they are, but am finding no mention in the docs/google, and am somewhat taken aback. ...jfree

vrrp stateful failover

2016-02-23 Thread Alex Needham
Hi The scenario is; web server that we need to get a large file from, a pair of haproxy load balancers in front of it in a master/backup configuration, with keepalived and conntrackd for fun. If a failover of a master to backup of haproxy occurs would we expect to see the download interrupted or

Proliferation of processes under systemd wrapper

2016-02-23 Thread BR Kumar
Couple of questions related to the systemd wrapper: 1) I noticed that it spawns a 2 level hierarchy of haproxy processes instead of a single child process. Can someone help understand why? 2) The problem arises when the intermediate haproxy process dies for any reason and the child process is ado

Re: SSL Termination of load-balanced queries against Active Directory LDAP

2016-02-23 Thread Nunya Bizniss
That appears to have done the trick. Thank you. I didn't realize I needed the 'ssl' modifier on the server bind line for the backend as well. On Tue, Feb 23, 2016 at 2:09 PM, Willy Tarreau wrote: > On Mon, Feb 22, 2016 at 11:54:01AM -0800, Nunya DamnedBizniss wrote: > > As the subject says, I'

[PATCH] BUG/MEDIUM: stats: stats bind-process doesn't propagate the process mask correctly

2016-02-23 Thread Cyril Bonté
With nbproc > 1, it is possible to specify on which process the stats socket will be bound using "stats bind-process", but the behaviour was not correct, ignoring the value in some configurations. Example : global nbproc 4 stats bind-process 1 stats socket /var/run/haproxy.sock With such a

Re: HTTP keep-alive reuse count & max-age

2016-02-23 Thread Willy Tarreau
Hi Michal, On Fri, Feb 19, 2016 at 09:04:00AM +0100, Micha?? Pasierb wrote: > Hi, > > Is it possible to influence how HAProxy handles HTTP keep-alives to backend > servers ? I want it to close TCP connection after x many HTTP requests. > Also a max-age time for single TCP connection cloud be usef

Re: RDP sessions issues

2016-02-23 Thread Willy Tarreau
Hi Jean, On Mon, Feb 15, 2016 at 12:59:30PM +0100, Jean Deslous-Paoli wrote: > The situation is the following: > - I implemented a session table shared between the two LB Servers > but it is not identical on either server > - Some users appear in both tables when most of the othe

Re: SSL Termination of load-balanced queries against Active Directory LDAP

2016-02-23 Thread Willy Tarreau
On Mon, Feb 22, 2016 at 11:54:01AM -0800, Nunya DamnedBizniss wrote: > As the subject says, I'm attempting to use SSL Terminated HAProxy to load > balance LDAP queries against Active Directory DCs. Because this LDAP is > not HTTP, I've chosen to use TCP Mode. Unfortunately, I have been unable > t

Re: Using operators in ACLs

2016-02-23 Thread Willy Tarreau
Hi Dmitry, On Fri, Feb 19, 2016 at 05:58:47PM +0300, Dmitry Sivachenko wrote: > Hello, > > I want to define ACL which will evaluate to true if a current number of > connections to a particular backend is greater than a number of usable > servers in that backend multiplied on some constant: > >

Fwd: SSL Termination of load-balanced queries against Active Directory LDAP

2016-02-23 Thread Nunya Bizniss
Running in debug mode returns this at startup: [WARNING] 053/110236 (21101) : Setting tune.ssl.default-dh-param to 1024 by default, if your workload permits it you should set it to at least 2048. Please set a value >= 1024 to make this warning disappear. Available polling systems : epoll : pref=

Re: SSL Termination of load-balanced queries against Active Directory LDAP

2016-02-23 Thread Lukas Erlacher
Hi, On 02/22/2016 08:54 PM, Nunya DamnedBizniss wrote: Is SSL Termination supported in TCP Mode? It certainly should be. https://www.reddit.com/r/sysadmin/comments/46c1im/issue_configuring_haproxy_frontend_to_active/ Can't see any obvious problems from skimming this. Please run haproxy in

RE: RDP sessions issues

2016-02-23 Thread Jean Deslous-Paoli
Hi, I understand you do not want to answer my questions but maybe you could redirect me towards a dedicated forum or another site ? Cordialement = Jean Deslous-Paoli Directeur des Systèmes d'Information Groupe 3S-Alyzia Mob: +33 6 89 42 14 70 Tel: +33 5 34 66 71 80