Re: [Pound Mailing List] Correct use of Threads for Pound 2.7

2017-05-08 Thread Scott McKeown
gt; >> https://linux.die.net/man/8/pound >> >> >> >> >> >> >> >> *From:* Aaron West [mailto:aa...@loadbalancer.org] >> *Sent:* Wednesday, May 03, 2017 2:02 PM >> *To:* pound@apsis.ch; wper...@valcom.com >> *Subject:* Re: [Pound

Re: [Pound Mailing List] Pound failing SSL Labs tests

2016-08-19 Thread Scott McKeown
Hi Stefan, Thanks I was looking for Joes link but couldn't find it. I'll build that now and see what I get thanks again. On 19 August 2016 at 13:00, qutic development <mailingli...@qutic.com> wrote: > > > Am 19.08.2016 um 11:57 schrieb Scott McKeown <sc...@loadbalancer.or

Re: [Pound Mailing List] SSL Backend not responding after upgrade from 2.6 to 2.7

2015-10-27 Thread Scott McKeown
nd ver. 2.6 > > NB. The backend can't be reconfigured to run http easily. > > > /Maciej -- To unsubscribe send an email with subject unsubscribe to > pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loa

Re: [Pound Mailing List] Connection reset on non-SSL sites instead of presenting first SSL mentioned in configuration

2015-10-23 Thread Scott McKeown
s could only be done during the SNI negotiation phase when > the server name is sent by the browser. Then I’d guess pound would check if > the sent server name has a certificate. If it doesn’t then a connection > reset or similar should happen. > > > > How would I achieve this?

[Pound Mailing List] Pound 2.7 and TProxy

2015-10-20 Thread Scott McKeown
g... detect_tproxy(): tproxy is is detected tproxy: available /etc/pound/pound.cfg line 8: unknown directive - aborted -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org Tel (UK) - +44 (0) 3303801064 (24x7) Tel (US) - +1 888.867.9504 (Toll Free)(24x7) pound_2.7_tproxy.patch Description: Binary data

Re: [Pound Mailing List] Pound 2.7 and TProxy

2015-10-20 Thread Scott McKeown
tly prohibited. If you have received this email > in error, do NOT read the information and please immediately notify sender > by telephone and email and immediately delete this email. If you are the > named recipient, you are NOT authorized to reveal any of this information >

Re: [Pound Mailing List] Crime vulnerability on 2.7f upstream

2015-07-10 Thread Scott McKeown
not support Forward Secrecy with the reference browsers. MORE INFO » https://en.wikipedia.org/wiki/Forward_secrecy -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org Tel (UK) - +44 (0) 3303801064 (24x7) Tel (US) - +1 888.867.9504 (Toll Free)(24x7)

Re: [Pound Mailing List] SSL Parameter

2015-05-21 Thread Scott McKeown
-21 13:17 GMT+02:00 Scott McKeown sc...@loadbalancer.org: Hi Daniel, First off what version on Pound are you running? There were a few patch files written a while back that should resolve most of these issues and if I remember correctly are in the latest build: Try adding the following

Re: [Pound Mailing List] SSL Parameter

2015-05-21 Thread Scott McKeown
need to change to get a better rating and make it more secure? thanks, Daniel -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org Tel (UK) - +44 (0) 3303801064 (24x7) Tel (US) - +1 888.867.9504 (Toll Free)(24x7)

Re: [Pound Mailing List] problem with a ev-ssl certificate /key

2014-12-09 Thread Scott McKeown
are welcome ! Kind regards fatcharly -- To unsubscribe send an email with subject unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org Tel (UK) - +44 (0) 3303801064 (24x7) Tel (US

Re: [Pound Mailing List] problem with a ev-ssl certificate /key

2014-12-09 Thread Scott McKeown
are welcome ! Kind regards fatcharly -- To unsubscribe send an email with subject unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org Tel (UK) - +44 (0) 3303801064 (24x7) Tel (US

Re: [Pound Mailing List] HTTPS BackEnd certificate issues

2013-12-05 Thread Scott McKeown
all data storage devices and destroy all hard copies. -- To unsubscribe send an email with subject unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] HTTPS redirect on HTTP

2013-08-05 Thread Scott McKeown
. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] cpu load issues still a issue?

2013-06-21 Thread Scott McKeown
for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] Current development status

2013-06-18 Thread Scott McKeown
. Thanx al lot, ps -- To unsubscribe send an email with subject unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] Current development status

2013-06-18 Thread Scott McKeown
/136765000/index_html Cheers, Andreas. On 18.06.2013 14:55, Scott McKeown wrote: Hi Peter, Welcome to Pound. I'm sure that Joe will jump in at some stage with more details but we use Pound ourselves and you can find that the community is quite active and supportive. Patches and fixes

Re: [Pound Mailing List] How to unsubscribe?

2013-06-18 Thread Scott McKeown
Hi Roberto, I'm sure its just a case of sending an eMail to pound@apsis.ch with the subject of 'unsubscribe' On 18 June 2013 14:52, Roberto Geraldo Pimenta Ribeiro Junior rpime...@senado.gov.br wrote: ** ** -- With Kind Regards. Scott McKeown Loadbalancer.org http

Re: [Pound Mailing List] send source IP of HTTP requests to web servers in the cluster

2013-05-21 Thread Scott McKeown
a pound server and wonder if it is possible to have the original source IP, as it is received by pound, relayed to the nginx server (so that it appears in the logs there)? regards, PAT -- *Pat Erler* Gtalk/G+: per...@gmail.com per...@gmail.comSkype: pat_erler -- With Kind Regards. Scott

Re: [Pound Mailing List] Too many open files errors running pound 2.5-1.1 on Ubuntu 12.04

2013-02-25 Thread Scott McKeown
...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] OpenSSL SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS patch

2013-02-20 Thread Scott McKeown
) ** ** Or name it something like SSLBeastAvoid 1 and swap the flag states. ** ** ** ** ** ** Joe ** ** *From:* Scott McKeown [mailto:sc...@loadbalancer.org] *Sent:* Tuesday, February 19, 2013 11:26 AM *To:* pound@apsis.ch *Subject:* Re: [Pound Mailing List] OpenSSL

Re: [Pound Mailing List] OpenSSL SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS patch

2013-02-19 Thread Scott McKeown
done the patch correctly. Not sure why it wouldn’t be working for you. ** ** Are you using SSL labs to test? ** ** ** ** ** ** Joe ** ** *From:* Scott McKeown [mailto:sc...@loadbalancer.org] *Sent:* Monday, February 18, 2013 6:07 AM *To:* pound@apsis.ch *Subject

[Pound Mailing List] OpenSSL SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS patch

2013-02-18 Thread Scott McKeown
); regfree(SSLHonorCipherOrder); regfree(SSLNoCompression); +regfree(SSLNoFragment); regfree(Ciphers); regfree(CAlist); regfree(VerifyList); Any help or advice would be most welcome. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] Send login and register to https - redirect loop

2013-01-15 Thread Scott McKeown
. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] Send login and register to https - redirect loop

2013-01-15 Thread Scott McKeown
, 2013, at 11:22 AM, Scott McKeown wrote: Hi Mark, Personally I would be tempted to use the 'Redirect' directive in your pound configuration file under the HTTP listener but keep the HTTPS listener as it is. So replace your HTTP Listener with something like this: ListenHTTP Address

Re: [Pound Mailing List] Send login and register to https - redirect loop

2013-01-15 Thread Scott McKeown
, 2013, at 11:22 AM, Scott McKeown wrote: Hi Mark, Personally I would be tempted to use the 'Redirect' directive in your pound configuration file under the HTTP listener but keep the HTTPS listener as it is. So replace your HTTP Listener with something like this: ListenHTTP Address

Re: [Pound Mailing List] Multiple SSL Certs

2012-10-12 Thread Scott McKeown
example of how I can achieve this, or the correct direction to be looking in? Many thanks, James. -- To unsubscribe send an email with subject unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http

Re: [Pound Mailing List] Direct Routing or DSR with pound

2012-10-09 Thread Scott McKeown
to do is just like this [1]. I did a test in a virtualbox environment. But the webserver is returning the answer to pound. I Already did the loopback things on webserver. But no luck. On Fri, Oct 5, 2012 at 3:40 PM, Scott McKeown sc...@loadbalancer.orgwrote: Hi Budiwijaya, If I understand

Re: [Pound Mailing List] Disabling SSL Compression (one line patch)

2012-10-05 Thread Scott McKeown
/ -- Coops -- To unsubscribe send an email with subject unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] SSL_CTX_use_PrivateKey_file Driving me insane

2012-09-27 Thread Scott McKeown
unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] SSL_CTX_use_PrivateKey_file Driving me insane

2012-09-27 Thread Scott McKeown
! This is just a test, the live site will use a real ssl cert. Thanks, Alan 2012-09-27 11:57, Scott McKeown skrev: Hi Alan, I'm sure that you will need to include the Private Key Chain in your PEM file to resolve this error. Have a look at http://www.digicert.com/ssl-**support/pem-ssl

Re: [Pound Mailing List] How to deny attacker?

2012-09-27 Thread Scott McKeown
iptabels would be the best option if your on a unix platform as this is at the kernel level and not software level which would save some processor overhead. Otherwise if you have an upstream firewall I would look at blocking the addresses or whole subnet there. Other than that Im not sure you can

Re: [Pound Mailing List] Puppet pound module

2012-09-25 Thread Scott McKeown
unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] redirect to holding page?

2012-09-25 Thread Scott McKeown
) if all web servers in a service are down? Cheers Mark. -- To unsubscribe send an email with subject unsubscribe to pound@apsis.ch. Please contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] BEAST attack patch for Pound 2.6 cannot get certificate

2012-09-20 Thread Scott McKeown
in an infinite loop. Using Firefox or even Safari returns something like: Firefox has detected that the server is redirecting the request for this address in a way that will never complete. From: Scott McKeown sc...@loadbalancer.orgmailto:sc...@loadbalancer.org Reply-To: pound

Re: [Pound Mailing List] BEAST attack patch for Pound 2.6 cannot get certificate

2012-09-20 Thread Scott McKeown
is worse. I cannot go from http to https or from https to http. So it's definitely something with pound! Previously I reinstalled pound with just plain 2.6 without any patches and it's the same problem! From: Scott McKeown sc...@loadbalancer.orgmailto:sc...@loadbalancer.org Reply

Re: [Pound Mailing List] BEAST attack patch for Pound 2.6 cannot get certificate

2012-09-20 Thread Scott McKeown
port 8080. And all https goes through pound as usual. I still have the same problem. Cannot redirect from http to https and vise versa (now that pound is running both ports). From: Scott McKeown sc...@loadbalancer.orgmailto:sc...@loadbalancer.org Reply-To: pound@apsis.chmailto:pound@apsis.ch

Re: [Pound Mailing List] BEAST attack patch for Pound 2.6 cannot get certificate

2012-09-19 Thread Scott McKeown
contact ro...@apsis.ch for questions. -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] Editing Information:

2012-09-14 Thread Scott McKeown
to limit downtime when making a new entry in the .cfg file? **2. **Is there another way to add/edit/manage the Pound.cfg file? Are there any web apps I can use that tie into Pound? ** ** Thanks for the help! ** ** Garrett H. -- With Kind Regards. Scott McKeown

Re: [Pound Mailing List] re-writing requests so i get the original IP address

2012-09-14 Thread Scott McKeown
? ** ** Any help much appreciated. ** ** Many thanks, KFCI ** ** -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] Session Tracking Issue

2012-09-06 Thread Scott McKeown
-- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org

Re: [Pound Mailing List] Subdomains SSL and one IP address

2012-09-06 Thread Scott McKeown
TimeOut 60 End End End ** ** Or something like this? -- With Kind Regards. Scott McKeown Loadbalancer.org http://www.loadbalancer.org