Re: [RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-27 Thread Emmanuel Hocdet
> Le 22 août 2019 à 14:40, Willy Tarreau a écrit : > > On Thu, Aug 22, 2019 at 11:36:00AM +0200, Geoff Simmons wrote: > >> I suspect that there are other ways that the authority TLV can be useful >> for haproxy besides the specific Varnish case. Someone connecting via >> TLS, for example,

Re: [RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-26 Thread Geoff Simmons
On 8/26/19 18:03, Emmanuel Hocdet wrote: > > Great to see TLS onloader continue. Working on it ... > About the TLS onloader configuration. If i understand the principle of > servers set to 0.0.0.0 and stick table: > The server configuration will look like: >server s0 0.0.0.0:0 ssl sni

Re: [RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-26 Thread Emmanuel Hocdet
HI Geoff, Willy Great to see TLS onloader continue. > Le 22 août 2019 à 16:33, Geoff Simmons a écrit : > > On 8/22/19 14:40, Willy Tarreau wrote: >> >>> I would suggest naming it something like fc_authority or >>> fc_pp_authority, to be specific about where it came from. > > Since you

Re: [RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-22 Thread Willy Tarreau
On Thu, Aug 22, 2019 at 04:33:13PM +0200, Geoff Simmons wrote: > On 8/22/19 14:40, Willy Tarreau wrote: > > > >> I would suggest naming it something like fc_authority or > >> fc_pp_authority, to be specific about where it came from. > > Since you used fc_pp_authority in an example further down,

Re: [RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-22 Thread Geoff Simmons
On 8/22/19 14:40, Willy Tarreau wrote: > >> I would suggest naming it something like fc_authority or >> fc_pp_authority, to be specific about where it came from. Since you used fc_pp_authority in an example further down, I'll take that as the choice (unless somebody yells). Seems better to me,

Re: [RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-22 Thread Willy Tarreau
On Thu, Aug 22, 2019 at 11:36:00AM +0200, Geoff Simmons wrote: > Spot on, that's the PR that I'm working on with my colleague Nils. Mine > is a PR to his PR, if that makes any sense; after review (assuming he > approves), the part about setting the authority TLV will go into the > Varnish PR. OK,

Re: [RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-22 Thread Geoff Simmons
On 8/21/19 21:50, Willy Tarreau wrote: > > Thus welcome to the list :-) Thanks for the informative and welcoming response. %^) > Just to know a bit more about your use case, thus your client speaks > in clear to haproxy by prepending a PPv2 header and lets haproxy serve > as a TLS "onloader" if

Re: [RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-21 Thread Willy Tarreau
Hello Geoff, On Wed, Aug 21, 2019 at 05:33:18PM +0200, Geoff Simmons wrote: > Hello to readers of the haproxy list, > > This is my first-ever mail to the list, Thus welcome to the list :-) > to propose my first-ever > contribution to the project, so I apologize in advance if anything here >

[RFC] setting the backend SNI from the client's authority TLV, when the target address was forwarded

2019-08-21 Thread Geoff Simmons
Hello to readers of the haproxy list, This is my first-ever mail to the list, to propose my first-ever contribution to the project, so I apologize in advance if anything here runs afoul of your customs. I hope I've come close enough to make it worth your while. What I'm proposing has been coded