RE: debugging ssl passthrough+haproxy

2014-11-21 Thread Lukas Tribus
We need to check how haproxy 1.5 ssl-hello-chk behaves, if it's still SSLv3 only, it would probably be a good time to upgrade this to TLS (at least v1.0). Enable SSLv3 on your server or disabled ssl-hello-chk to workaround the issue. It is, though I would rather add an additional keyword,

Re: haproxy 1.5.8 segfault

2014-11-21 Thread Godbach
Hi Willy, On 2014/11/21 14:35, Willy Tarreau wrote: Hi Godbach! On Fri, Nov 21, 2014 at 11:02:52AM +0800, Godbach wrote: Hi Willy, On 2014/11/19 2:31, Willy Tarreau wrote: On Tue, Nov 18, 2014 at 08:23:57PM +0200, Denys Fedoryshchenko wrote: Thanks! Seems working for me :) Will test more

Re: haproxy 1.5.8 segfault

2014-11-21 Thread Alexey Zilber
Hi Willy, Any ETA for the next release that incorporates this bugfix, or should I build from current source? Thanks! Alex On Fri, Nov 21, 2014 at 2:35 PM, Willy Tarreau w...@1wt.eu wrote: Hi Godbach! On Fri, Nov 21, 2014 at 11:02:52AM +0800, Godbach wrote: Hi Willy, On 2014/11/19

Re: haproxy 1.5.8 segfault

2014-11-21 Thread Willy Tarreau
Hi Alex, On Fri, Nov 21, 2014 at 05:35:32PM +0800, Alexey Zilber wrote: Hi Willy, Any ETA for the next release that incorporates this bugfix, or should I build from current source? No ETA set yet, and since I'm currently having my nose in 1.6 I'm pretty sure I'll find other bugs so I'd

How to negate options

2014-11-21 Thread Erwin Schliske
Hello, I have one question which I cannot solve on my own. In my defaults I set this options. option httplog option forwardfor option http-pretend-keepalive All of my frontends are http-frontends. Now I have a frontend, which I have to run with mode tcp. If I reload the config I get this

Re: How to negate options

2014-11-21 Thread Baptiste
On Fri, Nov 21, 2014 at 2:47 PM, Erwin Schliske erwin.schli...@sevenval.com wrote: Hello, I have one question which I cannot solve on my own. In my defaults I set this options. option httplog option forwardfor option http-pretend-keepalive All of my frontends are http-frontends. Now I

significant cpu use with path_reg acl with haproxy 1.5

2014-11-21 Thread konrad rzentarzewski
while migrating 1.4 = 1.5 i've came accross problem with regex lists, which worked seamlessly before. in every frontend there's a construct: acl worms_path url_reg -f /etc/haproxy/lists/worms_regex.lst acl invalid_path path_reg -f /etc/haproxy/lists/invalid_paths.lst block if

Re: significant cpu use with path_reg acl with haproxy 1.5

2014-11-21 Thread Willy Tarreau
Hi Konrad, On Fri, Nov 21, 2014 at 06:05:01PM +0100, konrad rzentarzewski wrote: while migrating 1.4 = 1.5 i've came accross problem with regex lists, which worked seamlessly before. in every frontend there's a construct: acl worms_path url_reg -f /etc/haproxy/lists/worms_regex.lst

Re: debugging ssl passthrough+haproxy

2014-11-21 Thread Willy Tarreau
On Fri, Nov 21, 2014 at 09:52:21AM +0100, Lukas Tribus wrote: We need to check how haproxy 1.5 ssl-hello-chk behaves, if it's still SSLv3 only, it would probably be a good time to upgrade this to TLS (at least v1.0). Enable SSLv3 on your server or disabled ssl-hello-chk to workaround

Re: significant cpu use with path_reg acl with haproxy 1.5

2014-11-21 Thread konrad rzentarzewski
On Fri, Nov 21, 2014 at 06:23:43PM +0100, Willy Tarreau wrote: There were changes to the acl part but in theory this should not impact performance, especially not like this. Are you sure you compiled 1.5 the same way as you did for 1.4 ? Please run haproxy -vv for both versions and output the

Re: significant cpu use with path_reg acl with haproxy 1.5

2014-11-21 Thread konrad rzentarzewski
On Fri, Nov 21, 2014 at 06:23:43PM +0100, Willy Tarreau wrote: BTW, you can even use PCRE_JIT in 1.5 which is even faster on most workloads. You need to set USE_PCRE_JIT=1 in addition to USE_PCRE=1. it seems that centos libs are too ancient for that :( include/common/regex.h:42:2: error:

SPDY and haproxy

2014-11-21 Thread Shawn Heisey
If we get mod_spdy installed on Apache, what's required to make that available through haproxy? The documentation I've found is somewhat confusing. From what I've been able to piece together, it sounds like we would need to have a virtualhost on Apache that provides SPDY on a different port from

RE: SPDY and haproxy

2014-11-21 Thread Lukas Tribus
Hi Shawn, If we get mod_spdy installed on Apache, what's required to make that available through haproxy? The documentation I've found is somewhat confusing. From what I've been able to piece together, it sounds like we would need to have a virtualhost on Apache that provides SPDY on a

Re: significant cpu use with path_reg acl with haproxy 1.5

2014-11-21 Thread Willy Tarreau
On Fri, Nov 21, 2014 at 06:33:46PM +0100, konrad rzentarzewski wrote: On Fri, Nov 21, 2014 at 06:23:43PM +0100, Willy Tarreau wrote: There were changes to the acl part but in theory this should not impact performance, especially not like this. Are you sure you compiled 1.5 the same way as

RE: significant cpu use with path_reg acl with haproxy 1.5

2014-11-21 Thread Lukas Tribus
On Fri, Nov 21, 2014 at 06:23:43PM +0100, Willy Tarreau wrote: There were changes to the acl part but in theory this should not impact performance, especially not like this. Are you sure you compiled 1.5 the same way as you did for 1.4 ? Please run haproxy -vv for both versions and output the

[SPAM] =??Q?Fa=E7a?= sua Silhouette trabalhar para =??Q?voc=EA.?= Ganhe dinheiro sem sair de casa

2014-11-21 Thread Loja Arte em DVD
Title: CAMEO DVDS EM PROMOCAO - FRETE GRATIS Caso no esteja conseguindo visualizar a mensagem, acesse aqui ou www.arteemdvd.com.br

[SPAM] This is for you

2014-11-21 Thread asaltalamacchia
All you have to do is registerto start earning today: http://www.binaryaffiliates.com/visit/?utm_brand=stockpairbta=11730r=v3 Opt out

FUZYON bagagerie Outdoor

2014-11-21 Thread 24 KRONOS
Version en ligne Ajouter nous votre carnet d’adresses LA KOURSE AUX BONS PLANS GRAND JEU Inscrivez-Vous Jusqu'au 8 Décembre Doublez vos Chances : Likez nous Vente du Samedi 22 Novembre Bagagerie Outdoor Jusqu'à -60% à partir de 5,94€Jusqu'à -60% Durée : 48H BIENTÔT Ouverture

Significant number of 400 errors..

2014-11-21 Thread Alexey Zilber
Hi All, I'm running v1.5.4 and I'm seeing a large amount of 400 BADREQ erros: Nov 21 22:46:06 srvr1 haproxy[28293]: 10.10.10.10:51184 [21/Nov/2014:22:45:50.323] www www/NOSRV -1/-1/-1/-1/16350 400 187 - - PRNN 445/445/0/0/3 0/0 {|||} BADREQ Nov 21 22:47:46 srvr1 haproxy[28293]: