Re: @Wolfssl: any plans to add "ECH (Encrypted client hello) support" and question about Roadmap

2023-06-01 Thread William Lallemand
On Thu, Jun 01, 2023 at 02:15:57PM +0200, Aleksandar Lazic wrote: > Hi, > > As we have now a shiny new LTS let's take a look into the future :-) > > As the Wolfssl looks like a good future alternative for OpenSSL is there > any plan to add ECH (Encrypted client hello) ( &g

@Wolfssl: any plans to add "ECH (Encrypted client hello) support" and question about Roadmap

2023-06-01 Thread Aleksandar Lazic
Hi, As we have now a shiny new LTS let's take a look into the future :-) As the Wolfssl looks like a good future alternative for OpenSSL is there any plan to add ECH (Encrypted client hello) ( https://github.com/haproxy/haproxy/issues/1924 ) into Wolfssl? Is there any Idea which feature

Re: Hello HAProxy Team! I have a question about one of your posts...

2021-09-20 Thread Vanessa Diwa
Hey there! Hope all is well, it's me again. I sent you an email a few days ago but never heard back. Will you be updating your post anytime soon? Would you be open to proposals, say adding our link as an additional resource to your post? Here is our article for your reference:

Re: Hello HAProxy Team! I have a question about one of your posts...

2021-09-12 Thread Vanessa Diwa
Hi HAProxy Team, I reached out a few days back regarding your remarkable post. Just checking in to see if you have received my previous email regarding your article https://www.haproxy.com/blog/power-your-consul-service-mesh-with-haproxy/ since I haven't received any feedback. I would love to

Hello HAProxy Team! I have a question about one of your posts...

2021-09-08 Thread Vanessa Diwa
Hi HAProxy Team, Vanessa from Toptal here! I promise this will be quick. I just read one of your posts - https://www.haproxy.com/blog/power-your-consul-service-mesh-with-haproxy/ and I was hoping that we could connect. I totally agree when you mention that Kubernetes makes configuring a service

Re: Hello ! May I ask you one question ?

2020-08-11 Thread Axel DUMAS
Hi ! Thanks to your help, my problem seem to be solved. https://code-examples.net/en/q/16962c http://www.tldp.org/HOWTO/html_single/TCP-Keepalive-HOWTO/ You were right. The problem of disconnections after some wait time was due to some timeouts parameters. In the "default" section, there was

Re: Hello ! May I ask you one question ?

2020-08-11 Thread Axel DUMAS
Hello ! Sorry for the subject of my email. Sometimes, I have some understanding concern in English. So you want all the configuration of HAProxy ? You can look at the attachment (haproxy.cfg). I have just used the basic configuration of HAProxy. And I have forgotten to mention the version

Re: Hello ! May I ask you one question ?

2020-08-10 Thread Tim Düsterhus
Axel, Am 10.08.20 um 19:02 schrieb Axel DUMAS: > Can I ask my question here ? Or do I have to write it in an other place ? This is the appropriate place. However I must admit that your email looked like spam based off the Subject at a first glance. > In order to test load-balancing, in the

Hello ! May I ask you one question ?

2020-08-10 Thread Axel DUMAS
Hello ! I am a new (french) user of HAProxy. I have learned some little things on it and on the configuration file and parameters. I wanted to use/learn it for my project, but I have some problems that I don't know how to solve. I have made some searchs...but I haven't found a corresponding

Hello

2019-08-31 Thread Linda Miller
Who designed your website "formilux.org"??? Regards, Linda

Hello

2019-08-21 Thread Victoria Sandoval
Have you removed push notification from your website www.formilux.org Regards, Victoria

Re: SPOE and modsecurity contrib Failed to decode HELLO frame

2018-08-17 Thread Aleksandar Lazic
ue - max-frame-size=16384] > 1534409877.495961 [04] Worker ready to process client messages > 1534409881.192419 [00] <1> New Client connection accepted and assigned to > worker 01 > 1534409881.192511 [01] <1> read_frame_cb > 1534409881.192596 [01] <1> New Frame of 129

SPOE and modsecurity contrib Failed to decode HELLO frame

2018-08-16 Thread Павел .
Worker ready to process client messages 1534409881.192419 [00] <1> New Client connection accepted and assigned to worker 01 1534409881.192511 [01] <1> read_frame_cb 1534409881.192596 [01] <1> New Frame of 129 bytes received 1534409881.192606 [01] <1> Decode HAProxy HELLO fra

Hello, I have a question about a post on feedjunkie.com

2018-02-07 Thread Anna Kucirkova
Hello there Your page http://feedjunkie.com/item/26333552/Where Athletes In The Worlds Top Sports Leagues Come F has some good references to some of the best athletes in the world so I wanted to get in touch with you. I've recently written an article about Roger Federer and was wondering

hello

2017-12-26 Thread missthe...@gmail.com
subscribe == 孙涛 +86 18516526973 missthe...@gmail.com ==

Hello

2016-08-26 Thread Jepdrp1
Hello, I am receiving a pop up states from Microsoft edge and HA Proxy statistics asking for my sign in. Is this you? what is this for? And how do I eliminate it? Thank You, James E Poirier

Hello, our company is specializing in the production of LEDT5 / T8 fluorescent lamp, ball bubble lamp, tube lamp, project-light lamp, mining lamp, etc...

2016-08-15 Thread 江丘朝
Dear purchasing manager, Hello, beautiful bright lighting lighting co., LTD., our company is a professional manufacturer of LED lighting, we want to provide high quality products and competitive price, hope to be a partner of your company. If you want to know more about our products, free

[SPAM] hello!

2015-05-05 Thread Natalia
hello! how are you today? What is your name? my name is Natalia, You frequently are on this site? I today wanted to talk to you in a chat, but you have already left a chat, Ithink that in the near future we with you shall talk, how you consider? You have yahoo or hotmail ID? if you write to me

[SPAM] Hello haproxy

2015-03-09 Thread Concetta
Hello) My name is Olga. Ilive in Moscow. I found out your page onthe Internet and I was curious about you. Tell me, please, what are you doing now and how do you spend your life ingeneral? In fact, you're interesting to me as a personality, and Iwant to communicate with you http

Re: Mix option httpchk and ssl-hello-chk

2014-10-02 Thread Willy Tarreau
On Fri, Sep 26, 2014 at 04:37:17PM +0200, Kevin COUSIN wrote: Here is my conf : backend bk_OWAP-SSL timeout server 30s timeout connect 5s mode http balance roundrobin option forwardfor #option ssl-hello-chk option httplog

Re: Mix option httpchk and ssl-hello-chk

2014-09-26 Thread Kevin COUSIN
Le 22/09/2014 15:44, Baptiste a écrit : On Mon, Sep 22, 2014 at 3:33 PM, Kevin COUSIN ki...@kiven.fr wrote: Hi list, Can I mix the option httpchk and ssl-hello-chk to check the health of an HTTPS website ? Thanks a lot Kevin C. Hi Kevin, No, you can't. It would be easier

Mix option httpchk and ssl-hello-chk

2014-09-22 Thread Kevin COUSIN
Hi list, Can I mix the option httpchk and ssl-hello-chk to check the health of an HTTPS website ? Thanks a lot Kevin C.

Re: Mix option httpchk and ssl-hello-chk

2014-09-22 Thread Baptiste
On Mon, Sep 22, 2014 at 3:33 PM, Kevin COUSIN ki...@kiven.fr wrote: Hi list, Can I mix the option httpchk and ssl-hello-chk to check the health of an HTTPS website ? Thanks a lot Kevin C. Hi Kevin, No, you can't. It would be easier to answer you with your backend

HELLO

2014-04-26 Thread kish patrick
Friend. I decided to share this lucrative opportunity with you, I am the foreign operations manager of our bank here in my country, Burkina Faso West Africa. i am married with four children. I want you to assist me in other to transfer the sum of into your reliable account as the business

RE: Query regarding extracting ssl hello sni.

2014-04-11 Thread Lukas Tribus
Hi, I would suggest that it will not harm even if you relax the check for client hello too as the old client can using SSL 3.0 is still supported and its according to RFC I disagree. SNI is documented as a TLS extension and unsupported in SSLv3. RFC3546 and RFC6066 are the relevant RFCs

Re: Query regarding extracting ssl hello sni.

2014-04-11 Thread Pravin Tatti
I too agree with your first comment relax only the check for record layer version as SNI is extensions for TLS protocols. I think the next version may or may not contain the same client hello format if it allows i don't have any issues if it doesn't allows then the code may crash or it may return

RE: Query regarding extracting ssl hello sni.

2014-04-11 Thread Lukas Tribus
Hi, I think the next version may or may not contain the same client hello format if it allows i don't have any issues if it doesn't allows then the code may crash or it may return bad value for SNI. I just suggested it for safety reasons its just my input. If HAproxy would crash, we

Re: Query regarding extracting ssl hello sni.

2014-04-11 Thread Pravin Tatti
and we should fix it. On Fri, Apr 11, 2014 at 4:32 PM, Lukas Tribus luky...@hotmail.com wrote: Hi, I think the next version may or may not contain the same client hello format if it allows i don't have any issues if it doesn't allows then the code may crash or it may return bad value

Re: Query regarding extracting ssl hello sni.

2014-04-11 Thread Willy Tarreau
On Fri, Apr 11, 2014 at 04:57:17PM +0530, Pravin Tatti wrote: Ok fine you can be forward compatible but i still don't agree its my personal opinion if I don't know what the packet format for next version why should I support it. But this was not the major issue for what i started the

RE: Query regarding extracting ssl hello sni.

2014-04-11 Thread Lukas Tribus
Hi, Ok fine you can be forward compatible but i still don't agree its my  personal opinion if I don't know what the packet format for next  version why should I support it. Because we are talking about a industry standard with a huge user base and it is very likely that next version will be

RE: Query regarding extracting ssl hello sni.

2014-04-11 Thread Lukas Tribus
Hi, It's not a matter of opinion but specification. If the packet format is specified as being exclusively for 3.0..3.3, then we should only match this. If it's specified as part of TLS for which only versions 3.0 to 3.3 are currently defined, then we must apply the default rule specified

Re: Query regarding extracting ssl hello sni.

2014-04-11 Thread Willy Tarreau
Hi Lukas, On Fri, Apr 11, 2014 at 03:17:32PM +0200, Lukas Tribus wrote: Hi, It's not a matter of opinion but specification. If the packet format is specified as being exclusively for 3.0..3.3, then we should only match this. If it's specified as part of TLS for which only versions 3.0 to

RE: Query regarding extracting ssl hello sni.

2014-04-11 Thread Lukas Tribus
Hi Willy, So in my opinion, since the protocol is designed to be backwards and forwards compatible, and uses minor version for newer extensions, there is no reason for limiting ourselves to TLSv1.2 for extensions that exist since 1.0 and will certainly continue to be supported by later

Re: Query regarding extracting ssl hello sni.

2014-04-10 Thread Willy Tarreau
Hi, On Thu, Apr 10, 2014 at 10:33:38AM +0530, Pravin Tatti wrote: Hi, The function smp_fetch_ssl_hello_sni() only supports record layer version and client hello version greater than or equal to 3.1. But as in the RFC5246 in appendix E says that TLS versions 1.0, 1.1, and 1.2, and SSL 3.0

Re: Query regarding extracting ssl hello sni.

2014-04-10 Thread Pravin Tatti
I think you still didn't understood the problem. There are two versions in SSL one is record layer hello version and the client hello version. Any application that support TLS versions 1.0, 1.1, 1.3 or SSLv3 (client hello version) may contain SSL 3.0 as the record layer version number and the once

Re: Query regarding extracting ssl hello sni.

2014-04-10 Thread Willy Tarreau
On Thu, Apr 10, 2014 at 06:30:26PM +0530, Pravin Tatti wrote: I think you still didn't understood the problem. There are two versions in SSL one is record layer hello version and the client hello version. Any application that support TLS versions 1.0, 1.1, 1.3 or SSLv3 (client hello version

RE: Query regarding extracting ssl hello sni.

2014-04-10 Thread Lukas Tribus
Date: Thu, 10 Apr 2014 15:22:43 +0200 From: w...@1wt.eu To: tattiprav...@gmail.com CC: haproxy@formilux.org Subject: Re: Query regarding extracting ssl hello sni. On Thu, Apr 10, 2014 at 06:30:26PM +0530, Pravin Tatti wrote: I think you still

RE: Query regarding extracting ssl hello sni.

2014-04-10 Thread Lukas Tribus
requires only SSLv3 or later in the record layer, but still requires at least TLSv1.0 in the client hello. I don't think any SNI capable client announces SSLv2 in the record layer or worse. I will submit the patch formally. Regards, Lukas

Re: Query regarding extracting ssl hello sni.

2014-04-10 Thread Pravin Tatti
I would suggest that it will not harm even if you relax the check for client hello too as the old client can using SSL 3.0 is still supported and its according to RFC and also note that the max supported TLS version is 3.3. I would suggest the below mentioned changes. 288c288 /* Check

Query regarding extracting ssl hello sni.

2014-04-09 Thread Pravin Tatti
Hi, The function smp_fetch_ssl_hello_sni() only supports record layer version and client hello version greater than or equal to 3.1. But as in the RFC5246 in appendix E says that TLS versions 1.0, 1.1, and 1.2, and SSL 3.0 are very similar and also if we check the last 2 paras as mentioned below

Hello Dear

2013-12-18 Thread Aamina Madani
Dear Friend, I am Miss. Aamina Madani the only surviving daughter of late Mr and Mrs.Hassan Madani. My Family members was killed on 2011, during the crisis that leads to the death of Muammar al-Gaddafi on October 20 2011. I am From Libya. My father left US$8.8 Million dollar Eight Million

hello

2013-10-31 Thread Alina Tekere
hello, goodday how are you doing today, hope you are doing good, my name is Alina, please i have a very important issue to discuss with you, please it is for our own good. i know you might not know me by mail, but please reply me so that i will explain myself and tell you why i mailed you

Invitation: Hello, @ Wed Oct 16, 2013 8pm - 9pm (barrister_oxf...@sify.com)

2013-10-16 Thread barrister_oxf...@sify.com
BEGIN:VCALENDAR PRODID:-//Google Inc//Google Calendar 70.9054//EN VERSION:2.0 CALSCALE:GREGORIAN METHOD:REQUEST BEGIN:VEVENT DTSTART:20131016T143000Z DTEND:20131016T153000Z DTSTAMP:20131016T142633Z ORGANIZER;CN=barrister_oxf...@sify.com:mailto:barrister_oxf...@sify.com

Haproxy ssl-hello-chk and check

2012-10-22 Thread Kevin COUSIN
Hi, I just setup an HAProxy for a RDS platform. I must set ssl-hello-chk option to get it works, but i can't set server check options with ssl-hello-chk, haproxy said haproxy[5059]: backend FARM has no server available. Is it normal ? Here is my conf: global log 127.0.0.1 local4

Re: Haproxy ssl-hello-chk and check

2012-10-22 Thread Baptiste
Hi, You forgot the directive 'check' on each server line. HAProxy only process health checks on the server you told it to do. cheers On Mon, Oct 22, 2012 at 3:34 PM, Kevin COUSIN ki...@kiven.fr wrote: Hi, I just setup an HAProxy for a RDS platform. I must set ssl-hello-chk option to get

Re: Haproxy ssl-hello-chk and check

2012-10-22 Thread Hervé COMMOWICK
Hello Kevin, You didn't set the check port, and as you specify server address without port number on server line, it can't work. Add check port 3389 on each server line but i think you can't use persist rdp-cookie if you want to use TLS as in http://support.microsoft.com/kb/895433 because Haproxy

Re: Hello

2012-09-17 Thread Applications
Dear applicant Thank you for your application to the above position. We will review all applications received shortly after the closing date and will be in contact with you thereafter. Please ensure that you have provided as much information as possible in your CV - this will help to ensure

Hello

2011-11-03 Thread Prince Ojie
Hello i AM PRINCE OJIE 20YRS OLD I HAVE VERY IMPORTANT ISSUE TO DISCUSS WITH YOU PLEASE KINDLY CONTACT ME URGENTLY ON E-MAIL : princeo...@live.com +233269420345 Regards Prince Ojie

HELLO

2011-04-07 Thread Anita Abdul
I am writing this letter out of a genuine desperation to find a reliable partner in an unfolding transaction. I seek your help and genuine co-operation to our mutual benefit and I believe that you will not letdown the trust and confidence I am about to repose on you. I am Anita,

HELLO

2011-04-05 Thread Anita Abdul
I am writing this letter out of a genuine desperation to find a reliable partner in an unfolding transaction. I seek your help and genuine co-operation to our mutual benefit and I believe that you will not letdown the trust and confidence I am about to repose on you. I am Anita,