> Apologies for not making this clearer, it is the SSLExplorer _Agent_ that 
> fails.

By agent you mean the client which is on the "frontend" from a HAProxy 
perspective?


> I can spin up an XP VM and test that IE 6 can connect to the
> SSLExplorer web interface over HAProxy 18-39 but as I'm not using SNI
> in the HAProxy config, I'm not sure how much use this would be I
> would presume that if 18-39 "broke" non SNI capable clients, others
> might have already noticed and reported it ?

The commit is pretty young, I don't think a lot of people already run
this code. Even if you don't use SNI, the commit could break SSL.

The thing we know for certain is that this commit breaks things for you,
and we also know for certain that this commit touches SNI/SSL, so it does
make sense to check with SNI capable/non capable clients.


Regards,

Lukas                                     

Reply via email to