Re: Removed health check in combination with load-server-state-from-file (Bug)

2017-08-25 Thread Tim Düsterhus
Hi as I did not receive any reply at all to my email from Aug 13 I thought I resend it (Quoted below). Can anyone at least verify that my bug report is valid? :-) Tim Am 13.08.2017 um 13:19 schrieb Tim Düsterhus: > Hi > > I run haproxy with 'load-server-state-from-file'. Before reloading >

Re: req.cook_cnt() broken?

2017-08-25 Thread Willy Tarreau
Hi Daniel, On Fri, Aug 25, 2017 at 12:47:41PM +0200, Daniel Schneller wrote: > On 24. Aug. 2017, at 01:50, Cyril Bonté wrote: > > > > You're right. currently, the code and the documentation don't say the same > > things. > > > > Can you try the attached patch ? > > > >

Re: Two way authentication issue

2017-08-25 Thread Lukas Tribus
Hello, Am 25.08.2017 um 17:27 schrieb Markus Rietzler: > you can do or use client authentication with ssl certificates on haproxy. My point is: you cannot enable SSL client certificate authentication on a specific URI. You need to server based renegotiation for that, which haproxy does not

Re: Two way authentication issue

2017-08-25 Thread Markus Rietzler
Am 25.08.17 um 08:49 schrieb Lukas Tribus: > Hello, > > > Am 25.08.2017 um 01:47 schrieb Keresztes Péter-Zoltán: >> Hello >> >> Basically what I need is when I browse /service/ws to use client certificate >> authentication otherwise for everything else to use normal ssl termination > > this is

Re: req.cook_cnt() broken?

2017-08-25 Thread Daniel Schneller
On 24. Aug. 2017, at 01:50, Cyril Bonté wrote: > > You're right. currently, the code and the documentation don't say the same > things. > > Can you try the attached patch ? > > -- > Cyril Bonté > Thanks for the patch! Tried against 1.8, 1.7.9, and 1.6.13 just now.

Re: Two way authentication issue

2017-08-25 Thread Lukas Tribus
Hello, Am 25.08.2017 um 01:47 schrieb Keresztes Péter-Zoltán: > Hello > > Basically what I need is when I browse /service/ws to use client certificate > authentication otherwise for everything else to use normal ssl termination this is not possible with Haproxy. Also, never ever bind to the