RE: Randomly added byte in GET request line with HAProxy 1.5 + OpenSSL

2013-06-14 Thread Lukas Tribus
Hi Holger, sounds like a tricky issue ... a few questions here: - has the Windows 7 box all the latest patches from MS? - any reason not to use openssl1.0.1e? - any security software (suites, software firewalls, anti-virus)   which may intercept the SSL/TLS session (basically: do you see your

Re: Randomly added byte in GET request line with HAProxy 1.5 + OpenSSL

2013-06-14 Thread Holger Just
Hi Lukas, Lukas Tribus wrote: sounds like a tricky issue ... indeed :) - has the Windows 7 box all the latest patches from MS? Yes. - any reason not to use openssl1.0.1e? I couldn't get it to compile, or in fact, I could compile it, but it would break at the `make test` step and I

RE: Randomly added byte in GET request line with HAProxy 1.5 + OpenSSL

2013-06-14 Thread Lukas Tribus
Hi Holger, There is a simple iptables on the box. By policy, we don't deploy any magic security snake oil I didn't mean the server or intermediate devices, I meant directly on the windows 7 client: *windows* software security solutions, which intercept SSL/TLS traffic on your local windows