Re: SSL custom dhparam problem

2015-05-24 Thread Willy Tarreau
Hi Lukas, On Sun, May 24, 2015 at 12:41:12PM +0200, Lukas Tribus wrote: For 1024, what we could do : - in 1.6 : we wouldn't provide one anymore, which means that users could only load it from a file they would generate if they need one ; You are implying that we will provide 2048 bit

RE: SSL custom dhparam problem

2015-05-24 Thread Lukas Tribus
Honestly, I'm opting for removing the DH fallback in haproxy altogether and simple always warn when the certificate (or a dedicated DH file parameter like nginx does, which was requested earlier this week and makes sense) does not have the DH parameters. I'm having a mixed opinion here.

Re: Re: SSL custom dhparam problem

2015-05-23 Thread Willy Tarreau
On Fri, May 22, 2015 at 10:58:47AM +0200, Remi Gacogne wrote: On Fri, May 22, 2015 at 09:10:36AM +0200, Hervé Commowick wrote: As a temporary solution, i have decided to use a custom DH param for each bind, but anyway, this clearly need a fix :) Did you test Rémi's patch to confirm

RE: SSL custom dhparam problem

2015-05-23 Thread Lukas Tribus
OK so now we need to find what to do in the end. From what I understood, just removing the lines was a test and is not viable because we'll always emit the warning, right ? Honestly, I'm opting for removing the DH fallback in haproxy altogether and simple always warn when the certificate (or a

Re: SSL custom dhparam problem

2015-05-22 Thread Hervé Commowick
diff --git a/src/ssl_sock.c b/src/ssl_sock.c index d0f4d01..c5bd2f9 100644 --- a/src/ssl_sock.c +++ b/src/ssl_sock.c @@ -1076,10 +1076,6 @@ int ssl_sock_load_dh_params(SSL_CTX *ctx, const char *file) if (dh) { ret = 1; SSL_CTX_set_tmp_dh(ctx, dh); -

Re: SSL custom dhparam problem

2015-05-22 Thread Hervé Commowick
Hey Willy, I confirm his patch work as expected, it just need to be modified a bit to apply on 1.5, but not a big deal. Hervé. On Fri, May 22, 2015 at 10:28 AM, Willy Tarreau w...@1wt.eu wrote: Hi Hervé, On Fri, May 22, 2015 at 09:10:36AM +0200, Hervé Commowick wrote: As a temporary

Re: SSL custom dhparam problem

2015-05-21 Thread Remi Gacogne
Hi Hervé, On 05/21/2015 10:11 PM, Hervé Commowick wrote: I encounter a problem with dhparam configuration, if i have 2 bind lines, a tune.ssl.default-dh-param 2048, and a custom group dhparam in one of the pem file, ALL bind lines will use 1024, the one with the custom group will work as

Re: SSL custom dhparam problem

2015-05-21 Thread Willy Tarreau
Hi Rémi, On Thu, May 21, 2015 at 11:19:15PM +0200, Remi Gacogne wrote: Hi Hervé, On 05/21/2015 10:11 PM, Hervé Commowick wrote: I encounter a problem with dhparam configuration, if i have 2 bind lines, a tune.ssl.default-dh-param 2048, and a custom group dhparam in one of the pem