Re: [ANNOUNCE] haproxy-1.8.13

2018-07-31 Thread Willy Tarreau
Hi Bertrand, On Tue, Jul 31, 2018 at 06:26:11PM +0100, Bertrand Jacquin wrote: > I know old farts don't change, but for the two cents, newer version of > OpenSSH (>= 6.7) and GnuPG (>=2.1.1) allow you to forward GnuPG agent over > SSH with reduce capacity to reduce the attack surface you are

Re: [ANNOUNCE] haproxy-1.8.13

2018-07-31 Thread Tim Düsterhus
Willy, Am 31.07.2018 um 20:32 schrieb Willy Tarreau: > That's where I disagree, it's exactly the same argument causing TLS to > appear on every web site even when not necessary, making people believe > they are safe while they are not. Right now you don't have this PGP > signature so you are

Re: [ANNOUNCE] haproxy-1.8.13

2018-07-31 Thread Bertrand Jacquin
On 31/07/2018 18:26, Bertrand Jacquin wrote: Hi Willy, On 30/07/2018 19:55, Willy Tarreau wrote: On Mon, Jul 30, 2018 at 07:41:33PM +0200, Tim Düsterhus wrote: Willy, Am 30.07.2018 um 18:05 schrieb Willy Tarreau: > A small update happened to the download directory, the sha256 of the > tar.gz

Re: [ANNOUNCE] haproxy-1.8.13

2018-07-31 Thread Willy Tarreau
On Tue, Jul 31, 2018 at 07:42:41PM +0200, Tim Düsterhus wrote: > Am 30.07.2018 um 20:55 schrieb Willy Tarreau: > > I know and I've already thought about it. But I personally refuse to store > > my PGP key on any exposed machine. Right now in order to tag, I have to > > SSH into an isolated

Re: [ANNOUNCE] haproxy-1.8.13

2018-07-31 Thread Tim Düsterhus
Willy, Am 30.07.2018 um 20:55 schrieb Willy Tarreau: > I know and I've already thought about it. But I personally refuse to store > my PGP key on any exposed machine. Right now in order to tag, I have to > SSH into an isolated machine, run "git pull --tags", create-release, and > "git push

Re: SNI matching issue when hostname ends with trailing dot

2018-07-31 Thread Lukas Tribus
Hello Warren, On Tue, 22 May 2018 at 15:48, Warren Rohner wrote: > The other day I inadvertently appended a trailing dot to the hostname > for one of our sites (e.g. https://www.example.com.), and when I did > this HAProxy returned the default cert to the browser rather than the > expected cert

Re: [ANNOUNCE] haproxy-1.8.13

2018-07-31 Thread Bertrand Jacquin
Hi Willy, On 30/07/2018 19:55, Willy Tarreau wrote: On Mon, Jul 30, 2018 at 07:41:33PM +0200, Tim Düsterhus wrote: Willy, Am 30.07.2018 um 18:05 schrieb Willy Tarreau: > A small update happened to the download directory, the sha256 of the > tar.gz files are now present in addition to the

Re: Possibility to modify PROXY protocol header

2018-07-31 Thread James Brown
I think if you use the `http-request set-src` directive it'll populate the PROXY headers in addition to the internal logging On Fri, Jul 27, 2018 at 7:05 AM bjun...@gmail.com wrote: > Hi, > > is there any possibilty to modify the client ip in the PROXY Protocol > header before it is send to a

IPBurger VPN Services | Sponsorship & Affiliate Proposal

2018-07-31 Thread Donald Fonseca
Hi! I'm Donald, the co-owner of IPBurger VPN services ( https://secure.ipburger.com/); We're a small but growing VPN company (Dedicated and Shared IP space) and we would be very grateful if you could include our company among similar services on your website. URL Example:

IPBurger VPN Services Linkback Programme

2018-07-31 Thread Donald Fonseca
Hi! I'm Donald, the co-owner of IPBurger VPN services ( https://secure.ipburger.com/); We're a small but growing VPN company (Dedicated and Shared IP space) and we would be very grateful if you could include our company among similar services on your website. URL Example: