[SPAM] Offre spéciale : recevez une tablette tactile avec votre abonnement au Point

2016-03-11 Thread Le Point
Afficher la version web. (http://trk.mix.jajaris.fr/view/yOM-89jgr.php) | Annuler votre abonnement. (http://trk.mix.jajaris.fr/usb/yOM-89jgr.php) | Signaler comme courrier indésirable. (mailto:ab...@dgcnit.fr) 40 numéros du Point la tablette Polaroid 7 pouces Polaroid pour 2,49 euros par semain

Re: [PATCH] BUG/MINOR: log: GMT offset not updated when entering/leaving DST

2016-03-11 Thread Willy Tarreau
Hi Benoit, On Sat, Mar 12, 2016 at 12:12:19AM +0100, Benoît GARNIER wrote: > It looked like they were emitted more than 1 hour apart, unlike with the fix: > <14>1 2016-03-27T01:59:58+01:00 bunch-VirtualBox haproxy 3381 - - Connect > ... > <14>1 2016-03-27T03:00:03+02:00 bunch-VirtualBox hapro

RE: [PossibleSpam] Re: SNI Support for Health Check on Backend Server

2016-03-11 Thread William D. Roush
OK, that’s odd, Debian’s backport fails to load the config as per your recommendation, but head of 1.6 does… They both report 1.6.3. However I’m still missing SNI on the health check using: server dev05 192.168.1.10:443 check ssl sni str(www.mysite.com) verify none William Roush | www.roushtec

Re: SNI Support for Health Check on Backend Server

2016-03-11 Thread Bryan Talbot
This passes config check for me using 1.6 HEAD btalbot-lt:haproxy-1.6$ cat haproxy.cfg global defaults timeout client 5s timeout server 5s timeout connect 5s mode http listen https bind :443 server dev05 192.168.1.10:443 check ssl sni str(prontotest.orthobanc.com) verify

RE: SNI Support for Health Check on Backend Server

2016-03-11 Thread William D. Roush
Using: "server dev05 192.168.1.10:443 check ssl sni str(www.mysite.com) verify none" Proxy 'www.mysite.com', server 'dev05' [/etc/haproxy/haproxy.cfg:62] verify is enabled by default but no CA file specified. If you're running on a LAN where you're certain to trust the server's certificate, ple

Re: 'show table' is unreliable?

2016-03-11 Thread Robert Samuel Newson
On 11 Mar 2016, at 22:43, Willy Tarreau wrote: > > Robert, > > On Fri, Mar 11, 2016 at 10:36:14PM +, Robert Samuel Newson wrote: >> yep, I bound everything but I still get warnings. There's a bug that might be >> related where binding stats doesn't work with stats bind-process, perhaps >> th

[PATCH] BUG/MINOR: log: GMT offset not updated when entering/leaving DST

2016-03-11 Thread Benoît GARNIER
[Please use the attached patch, my version of Thunderbird replaces tabs by spaces] GMT offset used in local time formats was computed at startup, but was not updated when DST status changed while running. For example these two RFC5424 syslog traces where emitted 5 seconds apart, just before an

Re: Question about build HAProxy for Solaris 11

2016-03-11 Thread Samuel Crowell
Thanks a lot for the response. I am getting an account with the website you provided to get the missing libraries. The feature I am looking for is the color variation between enabled and soft start. I left a prod server enabled but not soft started all night. It was my fault for not noticing there

Re: 'show table' is unreliable?

2016-03-11 Thread Willy Tarreau
Robert, On Fri, Mar 11, 2016 at 10:36:14PM +, Robert Samuel Newson wrote: > yep, I bound everything but I still get warnings. There's a bug that might be > related where binding stats doesn't work with stats bind-process, perhaps > that's my problem? Chad is right to insist on this, because C

Re: 'show table' is unreliable?

2016-03-11 Thread Robert Samuel Newson
ok, I'll try that, and looking forward to a 1.6.4, quite a few good fixes since 1.6.3. B. > On 11 Mar 2016, at 22:39, Cyril Bonté wrote: > > Hi, > > Le 11/03/2016 23:36, Robert Samuel Newson a écrit : >> yep, I bound everything but I still get warnings. There's a bug that might >> be related

Re: 'show table' is unreliable?

2016-03-11 Thread Cyril Bonté
Hi, Le 11/03/2016 23:36, Robert Samuel Newson a écrit : yep, I bound everything but I still get warnings. There's a bug that might be related where binding stats doesn't work with stats bind-process, perhaps that's my problem? Yes, there was a bug that will be fixed in next releases, which s

News about upcoming haproxy releases

2016-03-11 Thread Willy Tarreau
Hi all, I'm seeing some people rightfully complain that 1.6.3 is quite old and still plagued with some severe bugs for which fixes have been queued for some time. Time flies fast and bugs are not fixed as quickly as I'd like. So I'll release 1.6.4 and 1.5.16 with what we have right now. I think 1

Re: Only using map file when an entry exists

2016-03-11 Thread Nenad Merdanovic
Hello Neil, You seem to have missed my answer, so I am gonna top post this time :) http-request redirect location %[hdr(host),map(/etc/haproxy/redirect_host.map)] code 301 if { hdr(host),map(/etc/haproxy/redirect_host.map) -m found } Regards, Nenad On 03/11/2016 11:32 PM, Neil - HAProxy List wr

Re: 'show table' is unreliable?

2016-03-11 Thread Robert Samuel Newson
yep, I bound everything but I still get warnings. There's a bug that might be related where binding stats doesn't work with stats bind-process, perhaps that's my problem? > On 11 Mar 2016, at 22:33, Chad Lavoie wrote: > > Greetings, > > Ah, is the stats socket also bound to one process? For

Re: 'show table' is unreliable?

2016-03-11 Thread Chad Lavoie
Greetings, Ah, is the stats socket also bound to one process? For example "stats socket /var/run/haproxy.sock mode 0600 level admin process 4" to bind it to process 4. Otherwise the process your querying for the stats will bounce around, even if the process with the table doesn't. - Chad

Re: Only using map file when an entry exists

2016-03-11 Thread Neil - HAProxy List
Hello I've left a little time and no one has said anything more so time for me to act and submit a patch. I want to make functions that can be used in acls and take a map and provide has_key and, for completeness, has_value Are those names uncontroversial/ suitable and, i really hope, is this un

Re: SNI Support for Health Check on Backend Server

2016-03-11 Thread Bryan Talbot
There is a recently reported but for this. Try putting "verify none" AFTER the "sni" keyword in your server line. -Bryan On Fri, Mar 11, 2016 at 2:08 PM, William D. Roush < william.ro...@roushtech.net> wrote: > Hey Everybody, > > > Been struggling trying to get SNI to work with health checks, e

Re: Only using map file when an entry exists

2016-03-11 Thread Neil - HAProxy List
I'm amazed by the number of typos in one message. ;) On 3 Mar 2016 18:08, "Neil - HAProxy List" wrote: > Thanks Conrad, > > That sort of thing looks better that what I had, and I'll give it a go. > > I still think this is a bit long winded syntax for something that probably > quite a common thing

Re: 'show table' is unreliable?

2016-03-11 Thread Robert Samuel Newson
ah, yes, nbproc of 2 here, but I should be clear. The stick tables are in a proxy pinned to one single process, the other is used to handle TLS decoding. > On 11 Mar 2016, at 18:27, Chad Lavoie wrote: > > Greetings, > > That should have been "Do you have nbproc set and more then 1?", sorry. >

Re: Only using map file when an entry exists

2016-03-11 Thread Neil
Hello I've left a little time and no one has said anything more so time for me to act and submit a patch. I want to make functions that can be used in acls and take a map and provide has_key and, for completeness, has_value Are those names uncontroversia/ suitablel and, i really hope, is this un

SNI Support for Health Check on Backend Server

2016-03-11 Thread William D. Roush
Hey Everybody, Been struggling trying to get SNI to work with health checks, even using 1.6 and a server configuration of this: dev05 192.168.1.10:443 check ssl verify none sni str(www.mysite.com) It will still not send the SNI information to the backend server during health checks. Am I

Re: Question about build HAProxy for Solaris 11

2016-03-11 Thread Willy Tarreau
Hi Samuel, On Tue, Mar 01, 2016 at 08:51:09PM -0500, Samuel Crowell wrote: > I noticed that ya???ll have the binaries for HAProxy 1.4, is there any plan > to build the executables for newer versions (1.6, etc.)? No. The main reason is that my Ultra5 is extremely outdated. It still runs on solaris

Re: [PATCH] BUG/MEDIUM: cfgparse: wrong argument offset after parsing server "sni" keyword

2016-03-11 Thread Willy Tarreau
On Mon, Mar 07, 2016 at 10:13:22PM +0100, Cyril Bonté wrote: > Owen Marshall reported an issue depending on the server keywords order in the > configuration. > > Working line : > server dev1 : check inter 5000 ssl verify none sni req.hdr(Host) > > Non working line : > server dev1 : check inte

Re: HAProxy no longer working on new ubuntu servers, config has not changes.

2016-03-11 Thread Willy Tarreau
Hi Mike, On Tue, Mar 08, 2016 at 10:57:21AM -0500, Mike Curry wrote: > HAProxy is suddenly crashing on new Ubuntu (Digital Ocean, AWS - 14.04 and > 15.10) installs. I???ve had the same configuration working for over a year > now. I???ve posted all the logs and details below. Is there a new bug, or

Re: 'show table' is unreliable?

2016-03-11 Thread Chad Lavoie
Greetings, That should have been "Do you have nbproc set and more then 1?", sorry. - Chad On 03/11/2016 01:17 PM, Chad Lavoie wrote: Greetings, Do you have nbproc set or more then 1? If so, then each thread has its own stick table set; and depending on what thread handles it the values will

Re: 'show table' is unreliable?

2016-03-11 Thread Chad Lavoie
Greetings, Do you have nbproc set or more then 1? If so, then each thread has its own stick table set; and depending on what thread handles it the values will differ. Individual frontends can be set to a specific thread with bind-process (or for SSL a frontend specifically for SSL terminatio

'show table' is unreliable?

2016-03-11 Thread Robert Samuel Newson
Hi, I'm using haproxy 1.6.3 and think I've uncovered an issue. I use the stick table feature and as you can see from below, items appear and disappear randomly, these samples were taken less than a second apart. Obviously the items in the middle have at least 56 seconds remaining before expira

Re: [PATCH] MAJOR: ssl: add 'tcp-fallback' bind option for SSL listeners

2016-03-11 Thread Christopher Faulet
Hi, I've slightly updated my patch to improve it and to fix some inconsistencies. First of all, now "ssl-upgrade" and "no-ssl-upgrade" actions can be used on "tcp-request content" rules _AND_ "tcp-request connection" rules, in a frontend _OR_ a backend definition. Then, these actions are now cus

There is kind of a spam issue on this ML no?

2016-03-11 Thread Arnaud B.
On the last 2 or 3 days : https://lut.im/jsIGNMzLDL/OuRdpkM9ZpVTIH47 signature.asc Description: OpenPGP digital signature