HAProxy Stunnel end-to-end SSL

2010-10-20 Thread Clark, Ryan
I'm trying to use haproxy to load balance and content switch for 3 separate farms. The servers in the farms themselves have SSL certs on them. I'm using haproxy and stunnel to decrypt the https requests so haproxy knows where to forward the traffic. E.g https://site/test1 forwards to test1farm http

RE: HAProxy Stunnel end-to-end SSL

2010-10-20 Thread Mike Hoffs
Have u tried mode tcp ? Met een vriendelijke groet, Mike Hoffs

RE: HAProxy Stunnel end-to-end SSL

2010-10-20 Thread Clark, Ryan
Yes I have, even with the option ssl-hello-chk enabled. From: Mike Hoffs [mailto:m.ho...@mijn-sleutel.com] Sent: Wednesday, October 20, 2010 1:56 PM To: Clark, Ryan; haproxy@formilux.org Subject: RE: HAProxy Stunnel end-to-end SSL Have u tried mode tcp ? Met een vriendelijke groet

RE: HAProxy Stunnel end-to-end SSL

2010-10-20 Thread Clark, Ryan
From: Mike Hoffs [mailto:m.ho...@mijn-sleutel.com] Sent: Wednesday, October 20, 2010 2:11 PM To: Clark, Ryan Subject: RE: HAProxy Stunnel end-to-end SSL Hi Ryan, Note offside mailinglist, last days there was someone with simular situation; http://www.formilux.org/archives/haproxy/1010

RE: HAProxy Stunnel end-to-end SSL

2010-10-20 Thread Angelo Höngens
www.netmatch.nl -- From: Clark, Ryan [mailto:ryan.cl...@xerox.com] Sent: woensdag 20 oktober 2010 21:02 To: Mike Hoffs Cc: haproxy@formilux.org Subject: RE: HAProxy Stunnel end-to-end SSL I actually got it to work by using TCP mode. This might help other users to look

RE: HAProxy Stunnel end-to-end SSL

2010-10-20 Thread Clark, Ryan
I guess ACL's don't work in TCP mode... It doesn't work after all. Any others get ACL's to work in TCP mode? From: Mike Hoffs [mailto:m.ho...@mijn-sleutel.com] Sent: Wednesday, October 20, 2010 2:11 PM To: Clark, Ryan Subject: RE: HAProxy Stunnel end-to-end SSL Hi Ry

Re: HAProxy Stunnel end-to-end SSL

2010-10-20 Thread Kyle Brandt
m.ho...@mijn-sleutel.com > > Website: http://www.mijn-sleutel.com > > > > *Van:* Clark, Ryan [mailto:ryan.cl...@xerox.com] > *Verzonden:* woensdag 20 oktober 2010 20:00 > *Aan:* Mike Hoffs; haproxy@formilux.org > *Onderwerp:* RE: HAProxy Stunnel end-to-end SSL > > > &