TUVE LED PANEL LIGHTS FOR EU market

2015-05-26 Thread jielu79...@21cn.com

Re: Configure Haproxy to dynamically set backend server

2015-05-26 Thread Thierry FOURNIER
On Fri, 22 May 2015 19:06:59 + (UTC) Mrunmayi Dhume mrunmayi.dh...@yahoo.com wrote: Hello, I am using haproxy-1.6 with Lua. I have a use-case where I want to set the destination (backend server) very dynamically, based on certain layer 7 information (I am trying to avoid updating

Re: Configure Haproxy to dynamically set backend server

2015-05-26 Thread Pavlos Parissis
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 22/05/2015 09:06 μμ, Mrunmayi Dhume wrote: Hello, I am using haproxy-1.6 with Lua. I have a use-case where I want to set the destination (backend server) very dynamically, based on certain layer 7 information (I am trying to avoid

Re: A few thoughts on Haproxy and weakdh/logjam

2015-05-26 Thread Sean Decker
I think the new setting for a global dhparam file is a great idea. On May 26, 2015 11:12 AM, Remi Gacogne rgaco...@aquaray.fr wrote: Hi, On 05/23/2015 08:47 AM, Willy Tarreau wrote: Do you have any idea about the ratio of clients (on the net) which don't support ECDHE right now but

Re: A few thoughts on Haproxy and weakdh/logjam

2015-05-26 Thread Willy Tarreau
Hi Rémi, On Tue, May 26, 2015 at 05:11:36PM +0200, Remi Gacogne wrote: Hi, On 05/23/2015 08:47 AM, Willy Tarreau wrote: Do you have any idea about the ratio of clients (on the net) which don't support ECDHE right now but support DHE ? Basically, by totally removing DHE, we would be

Re: Configure Haproxy to dynamically set backend server

2015-05-26 Thread Mrunmayi Dhume
Thanks for your detailed reply Thierry. While this approach would solve the aspect of choosing the backend dynamically we still need to explicitly define each backend server separately in the haproxy config file. Our use-case involves having 100+ backends and we would prefer not to complicate

Re: Haproxy with Wildcard Cert HTTPS/HSTS Termination and HTTPS on the Backend

2015-05-26 Thread Werner Eisfeld
Hmmm... Yes, I have seen that. I have tried that exactly. haproxy returns the 502 Bad Gateway error. Is there anyway to dump the headers that are passing between haproxy and apache so that I can see what is missing? With the same config switched to tcpmode, everything works. In https terminated

DOC: set-log-level in Logging section preamble

2015-05-26 Thread Jim Freeman
As best I can tell, no mention is made of set-log-level in the Logging [Section 8] of the doc. Something akin to the following in the doc would have saved a good chunk of time/angst in addressing a logging issue I encountered : diff --git a/doc/configuration.txt b/doc/configuration.txt index

RE: Listening only server within backend

2015-05-26 Thread Lukas Tribus
Hi the list In my backend I've many servers, and I'd like to add some that receive a copy of all the requests arriving to the backend. Of course haproxy won't reply to them after sending the request. I don't find any option for 'server' in section 5 of the docs, that will allow me to

Re: A few thoughts on Haproxy and weakdh/logjam

2015-05-26 Thread Remi Gacogne
Hi, On 05/23/2015 08:47 AM, Willy Tarreau wrote: Do you have any idea about the ratio of clients (on the net) which don't support ECDHE right now but support DHE ? Basically, by totally removing DHE, we would be losing forward secrecy for: - Java = 6 ; - OpenSSL = 1.0.0 ; - Android = 3. Note

Sporadic 503 errors in logs

2015-05-26 Thread Jakov Sosic
Hi guys, I've noticed a lot of these kind of errors lately: May 26 23:03:32 localhost haproxy[22628]: CLIENT_IP:50399 [26/May/2015:23:03:27.909] FRONTEND BACKEND/SERVER 4344/0/-1/-1/4345 503 212 - - CCNN 271/75/13/4/0 0/0 {static.example.com|Mozilla/5.0 (Windows NT 6.1; WOW64)