Re: [VOTE] Release Apache Traffic Server 7.1.1 (RC1)

2017-09-14 Thread Reindl Harald
Am 14.09.2017 um 03:14 schrieb Igor Cicimov: ​​Hallelujah! I'm not the only one finding this guy annoying! If I was head of this project he would had been off the mailing list long time ago.​ Using language like this about people that gave him a great tool to use for FREE is just

Re: Positive conversations on the mailing list

2017-09-13 Thread Reindl Harald
Am 14.09.2017 um 01:07 schrieb Bryan Call: Let's keep the discussions positive and productive on the mailing lists. I understand that not all the features people want are in the releases. It is open source and we are happy to have code contributions. If you are not able to make code

Re: [VOTE] Release Apache Traffic Server 7.1.1 (RC1)

2017-09-13 Thread Reindl Harald
Am 14.09.2017 um 00:38 schrieb Leif Hedstrom: On Sep 12, 2017, at 2:41 PM, Reindl Harald <h.rei...@thelounge.net> wrote: Am 12.09.2017 um 22:31 schrieb Bryan Call: proxy.config.disable_configuration_modification was a feature that was requested and the group didn’t use it. We are pl

Re: Setup SSL certificate with ATS & Apache httpd

2017-09-13 Thread Reindl Harald
Am 13.09.2017 um 12:04 schrieb Alexander Yurchik: Hello I have ATS & Apache httpd installed and configured to run my site. Both runs on the same machine. ATS is 5.x version. ATS listens on 80 port and my config for ports is: CONFIG proxy.config.http.server_ports STRING 80 Now I obtained an

Re: [VOTE] Release Apache Traffic Server 7.1.1 (RC1)

2017-09-12 Thread Reindl Harald
]$ FUCK IT Am 12.09.2017 um 17:45 schrieb Reindl Harald: Am 02.09.2017 um 04:51 schrieb Miles Libbey: On Fri, Sep 1, 2017 at 6:40 PM, Reindl Harald <h.rei...@thelounge.net> wrote: Am 01.09.2017 um 22:43 schrieb Alan Carroll: Is that addressed by https://docs.trafficserver.apache.org/en/

Re: [VOTE] Release Apache Traffic Server 7.1.1 (RC1)

2017-09-12 Thread Reindl Harald
Am 02.09.2017 um 04:51 schrieb Miles Libbey: On Fri, Sep 1, 2017 at 6:40 PM, Reindl Harald <h.rei...@thelounge.net> wrote: Am 01.09.2017 um 22:43 schrieb Alan Carroll: Is that addressed by https://docs.trafficserver.apache.org/en/latest/admin-guide/files/records.config.en.html?hig

ECDSA/RSA Dual-Stack

2017-09-09 Thread Reindl Harald
what the hell - not enough that you can't simply say /folder/backendname/*.pem that below don't work too while in case of httpd it's pretty easy: SSLCertificateFile "/var/lib/letsencrypt/certs/rhsoft.conf_rsa.pem" SSLCertificateFile

ssl_multicert.config: why not just wildcard support?

2017-09-09 Thread Reindl Harald
frankly why in the world can't you just say "take certificates from this and that folder"? we have at least 4 backend servers which will soon start to generate their certificates and sync them via rsync to /var/lib/letsencrypt/hostname/ on the ATS machine and it makes no sense at all that

Re: ATS proxy closes the connection "close" even if client sends "keep-alive"

2017-09-05 Thread Reindl Harald
Am 04.09.2017 um 17:46 schrieb Ananth Laxminarasimhan (alaxmina): < HTTP/1.1 407 Proxy Authentication Required < Date: Mon, 04 Sep 2017 11:21:22 GMT < Connection: close < Via: http/1.1 POD128-CentOS7-01.ibwsa (ApacheTrafficServer/6.2.1) < Server: ATS/6.2.1 < Proxy-Authenticate: NTLM <

Re: ATS proxy closes the connection "close" even if client sends "keep-alive"

2017-09-03 Thread Reindl Harald
Am 03.09.2017 um 15:28 schrieb Ananth Laxminarasimhan (alaxmina): What happens is that even though the client sends a “Connection: keep-alive”, ATS seems to be returning a “Connection: close” which results in the connection getting closed keep-alöive is finally a descision of the server and

Re: [VOTE] Release Apache Traffic Server 7.1.1 (RC1)

2017-09-01 Thread Reindl Harald
Am 02.09.2017 um 04:51 schrieb Miles Libbey: On Fri, Sep 1, 2017 at 6:40 PM, Reindl Harald <h.rei...@thelounge.net> wrote: Am 01.09.2017 um 22:43 schrieb Alan Carroll: Is that addressed by https://docs.trafficserver.apache.org/en/latest/admin-guide/files/records.config.en.html?hig

Re: [VOTE] Release Apache Traffic Server 7.1.1 (RC1)

2017-09-01 Thread Reindl Harald
, Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>> wrote: frankly can somebody fix that after FIVE YEARS of complaints? with 7.1 "/usr/bin/traffic_ctl config reload" don't do anything, with 7.0 it also complaints like below on startup that

Re: [VOTE] Release Apache Traffic Server 7.1.1 (RC1)

2017-08-31 Thread Reindl Harald
t() failed #2457 - Cherry pick a set of Catch based commits to 7.1 #2458 - Coverity: CID 1380042:Resource leaks (RESOURCE_LEAK) #2459 - fixing memory leak when ATS serves stale records #2460 - S3_auth:uri(En|De)code() pass by ref,not val(master) -- Reindl Harald the lounge interact

Re: unsubscribe

2017-08-22 Thread Reindl Harald
Am 22.08.2017 um 23:30 schrieb Provedor Bogus: your name is program? do it yourself as anybody else List-Help: List-Unsubscribe: List-Post: List-Id:

Re: Slow HTTP DoS: Trafficserver needs something like mod_reqtimeout

2017-08-21 Thread Reindl Harald
timeout_out INT 300" so i have no idea why the script below leads to 5 log-entries and trafficserver let the client sit and wait all the time without any response Am 21.08.2017 um 16:15 schrieb Reindl Harald: the current timeout configs are terrible 16:04:00 - request start 16:05:0

Re: Slow HTTP DoS: Trafficserver needs something like mod_reqtimeout

2017-08-21 Thread Reindl Harald
saction_active_timeout_out INT 0 CONFIG proxy.config.http.accept_no_activity_timeout INT 1 CONFIG proxy.config.http.background_fill_active_timeout INT 0 CONFIG proxy.config.http.background_fill_completed_threshold FLOAT 0.0 Am 21.08.2017 um 15:33 schrieb Reindl Harald: on httpd this is ju

Slow HTTP DoS: Trafficserver needs something like mod_reqtimeout

2017-08-21 Thread Reindl Harald
on httpd this is just a single config line https://httpd.apache.org/docs/2.4/mod/mod_reqtimeout.html RequestReadTimeout header=5-15,MinRate=500 body=20,MinRate=500 while we have ratelimiting and max-connection per ip/subnet to solve that problems on the firewall instead in the attacked

Re: [VOTE] Release Apache Traffic Server 7.1.0 (RC1)

2017-07-18 Thread Reindl Harald
Am 18.07.2017 um 10:35 schrieb Leif Hedstrom: I've prepared a release for 7.1.0 (RC1) which is the next major version of Apache Traffic Server. As per our new release schedule and process, v7.1.x is an Long-Term Support (LTS) release. This is detailed in our Release looks good so far on

Re: SSL for trafficserver

2017-06-30 Thread Reindl Harald
"my origin server has CA signed wild card certificate, so what kind of certificate should I install on traffic server (ex:self signed or ca signed) and what are the steps to install certificate?" that is a very strange question a) if you don't want warnings on the clients self-signed is not

Re: ATS 7.0.0 on CentOS Starting Error libtcl8.6.so

2017-06-19 Thread Reindl Harald
Am 20.06.2017 um 06:07 schrieb Naveen: Hello I already have the files and linker as below and *did* you run ldconfig too? i guess no [root@prxy bin]# cd /etc/ld.so.conf.d/ [root@prxy ld.so.conf.d]# ls -ltr total 28 -rw-r--r--. 1 root root 22 Jun 10 2014 qt-x86_64.conf -rw-r--r--. 1

Re: ATS 7.0.0 on CentOS Starting Error libtcl8.6.so

2017-06-19 Thread Reindl Harald
Am 19.06.2017 um 17:13 schrieb Norbert Naveen: I have setup ATS 7.0.0. on Cent OS 7.3 ./configure --prefix=/opt/ats --with-tcl=/opt/ActiveTcl-8.6/lib When I Start the Server [root@prxy trafficserver]# /opt/ats/bin/trafficserver start Starting Apache Traffic Server:

Re: http2 support on chrome

2017-03-12 Thread Reindl Harald
. and chrome choose http 1.1. On Sun, Mar 12, 2017 at 6:40 PM, Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>> wrote: > > > Am 12.03.2017 um 10:55 schrieb 彭勇: >> >> i setup a ATS, then enable ssl and http2. >&

Re: http2 support on chrome

2017-03-12 Thread Reindl Harald
Am 12.03.2017 um 10:55 schrieb 彭勇: i setup a ATS, then enable ssl and http2. curl shows ATS works fine. and chrome 56 shows it use protocal http 1.1 to connect to ATS. is there any ALPN / NPN negotiating problem between chrome and ATS? how can i serve http2 for chrome? i doubt that you

Re: Configuraing 1g*N uplink cache server with ATS

2017-02-07 Thread Reindl Harald
Am 08.02.2017 um 03:27 schrieb Rebirthing: Hello :). I'm trying to configure a linux-based router with ATS in transparency mode. The router will be have N(3~7 of 1Gbs) up-links. I'm curious that ATS could handle the traffics. Because.. many traffics will be occurred on each line. Is there

Re: upstart vs systemd: ATS best service practice

2017-01-30 Thread Reindl Harald
] Manager {0x7feb55f48940} NOTE: [Alarms::signalAlarm] Server Process born *From:* Reindl Harald <h.rei...@thelounge.net> *Sent:* Monday, January 30, 2017 12:35:26 PM *To:* users@trafficserver.apache.org *Subjec

Re: upstart vs systemd: ATS best service practice

2017-01-30 Thread Reindl Harald
Am 30.01.2017 um 16:57 schrieb David Carlin: Reindl, I think there is a setting 'proxy.config.disable_configuration_modification = 1' to prevent ATS from modifying the config files:

Re: upstart vs systemd: ATS best service practice

2017-01-29 Thread Reindl Harald
Am 29.01.2017 um 23:09 schrieb Lerner, Steve: Friends, Does anyone want to share their systemd and upstart configurations for ATS? I have been digging and haven’t found an official statement about ‘service-izing’ ATS… Do we have an official recommendation for enabling ATS as a service on

Re: What dangers (if any) to enabling OCSP Stapling?

2017-01-23 Thread Reindl Harald
the try-later hence the two params in my httpd config and as long nobody confirms that behavior for ATS i would not enable stapling at all - On Jan 23, 2017, at 1:12 PM, Reindl Harald h.rei...@thelounge.net wrote: Am 23.01.2017 um 18:40 schrieb Jered Floyd: OCSP Stapling is off

Re: What dangers (if any) to enabling OCSP Stapling?

2017-01-23 Thread Reindl Harald
Am 23.01.2017 um 18:40 schrieb Jered Floyd: OCSP Stapling is off by default in ATS. What risks, if any, are there to enabling it? Given that my issuer supports OCSP and many browsers support OCSP and OCSP Stapling, it seems like enabling it is the "safest" option. Is there a reason it is not

Re: Facing problem in running ATS

2017-01-17 Thread Reindl Harald
Am 17.01.2017 um 00:08 schrieb salil GK: I have stopped the other instance that is running ( 26997 ). Then I tried to run this command. Then I am getting a core dump of traffic_server ~/apns/etc # env | grep TS TS_ROOT=/tandberg/apns/ ~/apns/etc # /trafficserver/bin/traffic_manager [E.

ATS 7.0 reload remap.conf with read-only /etc

2017-01-13 Thread Reindl Harald
frankly can you stop all that write access to /etc/trafficserver/ and just *read* the configs - obviously the realod is stopped because without touch the file it is not mentioned at all in the logfile and only the whining about "WARNING: open file: /etc/trafficserver/records.config.tmp to

unbundeled lua-jit

2017-01-11 Thread Reindl Harald
with ATS 7.0 lua-jit became obviously mandatory and is built with ATS LUAJIT_CPPFLAGS:-I$(top_srcdir)/lib/luajit/src LUAJIT_LDFLAGS: EXTRA_CC_LDFLAGS: EXTRA_CXX_LDFLAGS: -rdynamic LIBTOOL_LINK_FLAGS: -R/usr/lib64 frankly when luajit is installed on the build-machine use

Re: compress traffic between haproxy and trafficserver

2017-01-10 Thread Reindl Harald
Am 10.01.2017 um 15:48 schrieb Yossi Nachum: I have apache traffic server around the world that are behind haproxy servers. Can I compress the traffic between haproxy and the trafficserver to save bandwidth? makes not much sense when correctly configured the backend server does compresison

Re: how make backend applications aware about tls-offloading

2017-01-07 Thread Reindl Harald
Am 08.01.2017 um 00:31 schrieb Yann Ylavic: On Sun, Jan 8, 2017 at 12:22 AM, Reindl Harald <h.rei...@thelounge.net> wrote: ok, so we need to continue the code below and set the option in every tls-offloaded application - intention of this thread was maybe get this transparent which

Re: how make backend applications aware about tls-offloading

2017-01-07 Thread Reindl Harald
Am 07.01.2017 um 22:53 schrieb Yann Ylavic: On Sat, Jan 7, 2017 at 9:30 AM, Reindl Harald <h.rei...@thelounge.net> wrote: something like below where "X-TLS-Offloading" is only evaluated from "RemoteIPInternalProxy" pyhsical addressess RemoteIPHeader X-For

Re: how make backend applications aware about tls-offloading

2017-01-07 Thread Reindl Harald
clue - On Jan 7, 2017, at 3:30 AM, Reindl Harald h.rei...@thelounge.net wrote: * Apache Trafficserver in front * ATS configured for TLS-offloading * connection to backend-httpd on the LAN unencrypted * mod_remoteip correctly configured on backend httpd is there any way to make the bac

how make backend applications aware about tls-offloading

2017-01-07 Thread Reindl Harald
* Apache Trafficserver in front * ATS configured for TLS-offloading * connection to backend-httpd on the LAN unencrypted * mod_remoteip correctly configured on backend httpd is there any way to make the backend php application aware that in fact $_SERVER['HTTPS'] and $_SERVER['REQUEST_SCHEME']

Re: benchmark ATS

2016-12-13 Thread Reindl Harald
Am 13.12.2016 um 09:45 schrieb Di Li: When I doing some benchmark for outbound proxy, and has http_cache enabled, well, first of all, the performance are pretty low, I guess I didn’t do it right with the cache enabled, 2nd when I use wrk to have 512 connection with 40 thread to go through proxy

Re: luajit vs lua in ATS

2016-12-08 Thread Reindl Harald
it's ridiculous to rely on configs which obviously could be created at start from scratch as well as write configs in scripting languages - especially when those scripting languages are part of the bundeled source instead using system libraries On Thu, Dec 8, 2016 at 3:55 PM, Reindl Harald

Re: luajit vs lua in ATS

2016-12-08 Thread Reindl Harald
Am 08.12.2016 um 20:05 schrieb Shu Kit Chan: luajit is built-in so ts-lua will run without you doing anything and it's bad that it is built-in with no longer a way to disable it in ./configure - there are setups which don't need any fancy plugins and scripting languages but just a fast

readonly /etc and "Creation of a placeholder failed : Permission denied"

2016-12-08 Thread Reindl Harald
7.0.0: logging.config metrics.config FATAL: [RollBack::Rollback] Unable to find configuration file metrics.config. Creation of a placeholder failed : Permission denied __ the following *really* should not be needed to get it started frankly there

compile warnings

2016-12-08 Thread Reindl Harald
7.0.0 - GCC6 - maybe some of them are only visible if you biuld with LTO but in any case worth a look ../../iocore/utils/I_Machine.h:51:8: warning: type 'struct Machine' violates the C++ One Definition Rule [-Wodr] UglyLogStubs.cc:68:8: note: a different type is defined in another translation

files in /usr/man -> Re: [ANNOUNCE] Apache Traffic Server 6.2.0 is released!

2016-11-03 Thread Reindl Harald
https://issues.apache.org/jira/browse/TS-5029 Am 28.07.2016 um 11:39 schrieb James Peach: On Jul 27, 2016, at 7:48 PM, Reindl Harald <h.rei...@thelounge.net> wrote: /usr/man? seriously? such bugs would become obvious by just build a simple RPM with the same SPEC as before Fehle

don't start with read-only /etc -> Re: [ANNOUNCE] Apache Traffic Server 6.2.0 is released!

2016-11-03 Thread Reindl Harald
::startProxy] Launching ts process [Aug 5 17:35:29.012] Manager {0x7f2183e76900} NOTE: [LocalManager::pollMgmtProcessServer] New process connecting fd '14' [Aug 5 17:35:29.012] Manager {0x7f2183e76900} NOTE: [Alarms::signalAlarm] Server Process born -- Reindl Harald the lounge interactive design

Re: Query strings are not forwarded

2016-10-27 Thread Reindl Harald
Am 27.10.2016 um 13:05 schrieb Randeep: Our urls are like http://jitp1.dmain.com/dashw/abpnews/manifest.mpd?starttime=147745440=147745620 We need to cache only

Re: Caching for Database

2016-10-14 Thread Reindl Harald
Am 14.10.2016 um 16:40 schrieb $ubbu: Is it possible to cache database along with web caching in ATS? not the job of a web-proxy - how should it - it don't see anything about databases behind the websites it caches http://dev.mysql.com/doc/refman/5.7/en/query-cache.html

Re: Issue with TS caching

2016-10-03 Thread Reindl Harald
for the moment. The question is also why doesn't TS refresh if I send a "no-cache" request ? shouldn't it by default respect this header value ? On Mon, Oct 3, 2016 at 1:23 PM, Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>> wrote: Am 03.10.2016 um 1

Re: trafficserver and wordpress not work

2016-09-28 Thread Reindl Harald
Am 28.09.2016 um 21:06 schrieb pa...@ula.ve: I found the site and where are the logs of ATS Thanks .. which gives me the following error information, log? Thank you again 20160928.15h00m21s RESPONSE: sent 10.10.17.104 status 404 (Not Found on Accelerator) for

Re: trafficserver and wordpress not work

2016-09-20 Thread Reindl Harald
Am 20.09.2016 um 16:50 schrieb pa...@ula.ve: Am 15.09.2016 um 22:23 schrieb pa...@ula.ve: trafficserver and wordpress not work? a reverse proxy by definition is application agnostic you need to describe your probkem and config Hi thanks the problem is that the reverse proxy works

Re: Does ATS support URLs longer than 8K?

2016-09-19 Thread Reindl Harald
Am 19.09.2016 um 20:23 schrieb Miles Libbey: A few more settings to look at: proxy.config.cache.max_doc_size proxy.config.http.max_post_size (if they are POSTs?) that's all nice *but* a URL longer than 8K is a fractal of bad design of whatever applications doing that instead using POST for

Re: trafficserver and wordpress not work

2016-09-15 Thread Reindl Harald
Am 15.09.2016 um 22:23 schrieb pa...@ula.ve: trafficserver and wordpress not work? a reverse proxy by definition is application agnostic you need to describe your probkem and config

Re: [PROPOSAL] Removing clustering support in7.0.0

2016-08-29 Thread Reindl Harald
Am 30.08.2016 um 01:07 schrieb Nguyen, Hai: We are using clustering to share configuration settings in environments that do load balancing across multiple proxies. Administrators that have large deployments would need to configure every proxy manually no they just would use a config

Re: [ANNOUNCE] Apache Traffic Server 6.2.0 is released!

2016-08-05 Thread Reindl Harald
Am 28.07.2016 um 11:41 schrieb James Peach: On Jul 27, 2016, at 8:03 PM, Reindl Harald <h.rei...@thelounge.net> wrote: anyways, ATS 6.2.0 no longer works with a readonly /etc Jul 27 12:01:20 buildserver traffic_manager[8836]: NOTE: --- Manager Starting --- Jul 27 12:01:20 build

Re: [ANNOUNCE] ATS v7.0.0 HTTP/2 will be on by default

2016-07-27 Thread Reindl Harald
Am 27.07.2016 um 13:07 schrieb Bryan Call: As we have discussed at ATS Summits, ATS 7.0.0 will have HTTP/2 enabled by default. Here is the Jira Ticket for the change: TS-3620. how is this supposed to work in case of non-TLS pages since most browsers make TLS mandatory for HTTP/2

Re: [ANNOUNCE] Apache Traffic Server 6.2.0 is released!

2016-07-27 Thread Reindl Harald
traffic_manager, retrying in 60 second(s) Am 27.07.2016 um 11:48 schrieb Reindl Harald: /usr/man? seriously? such bugs would become obvious by just build a simple RPM with the same SPEC as before Fehler beim Bauen des RPM: Datei nicht gefunden: /home/builduser/rpmbuild/BUILDROOT/trafficserver-6.2.0-2

Re: [ANNOUNCE] Apache Traffic Server 6.2.0 is released!

2016-07-27 Thread Reindl Harald
/usr/man? seriously? such bugs would become obvious by just build a simple RPM with the same SPEC as before Fehler beim Bauen des RPM: Datei nicht gefunden: /home/builduser/rpmbuild/BUILDROOT/trafficserver-6.2.0-2.fc24.20160727.rh.x86_64/usr/share/man/man3/*

Re: Centos 5.8 and Traffic Server SSL

2016-07-22 Thread Reindl Harald
Am 22.07.2016 um 15:02 schrieb Steve Malenfant: I'm trying to connect and older proprietary system running on Centos 5.8 to an internal CDN running ATS 5.3.2 via https. Somehow I can connect to a bunch of different sites, but not to ATS. I don't know much about SSL, but I can't get pass

Re: ATS and AJP

2016-07-18 Thread Reindl Harald
Am 18.07.2016 um 19:52 schrieb Pierre Smits: How do I configure the ATS server to sit in front of a Tomcat server and use the AJP protocol? since ATS is a *http proxy* i doubt you can avoid ATS -> httpd with mod_jk or similar signature.asc Description: OpenPGP digital signature

Re: SSL and Reverse Proxy

2016-07-18 Thread Reindl Harald
) "Yes, give me a ciphersuite that works with legacy / old software." i gave you one which is here in prodcution for a ton of domains and several services! -Original Message----- From: Reindl Harald [mailto:h.rei...@thelounge.net] Sent: Monday, 18 July 2016 4:52 PM

Re: SSL and Reverse Proxy

2016-07-18 Thread Reindl Harald
Am 18.07.2016 um 09:37 schrieb Chee, Anthony [COMP]: CONFIG proxy.config.ssl.server.cipher_suite

Re: iowait

2016-07-14 Thread Reindl Harald
Am 14.07.2016 um 20:54 schrieb Leif Hedstrom: On Jul 14, 2016, at 12:11 PM, Randeep wrote: Thanks Harald. I'll check the raid configuration. We recommend not using RAID for the ATS cache, it’s desirable to let ATS deal with that. I.e. just give it some JBOD’s.

Re: basic regex_map vs map performance

2016-07-14 Thread Reindl Harald
Am 14.07.2016 um 19:21 schrieb Leif Hedstrom: I believe Bryan and Phil made some performance improvements with PCRE’s, so if your platform has a modern PCRE library, it will be able to use the JIT that it supports. beware of bugs like https://bugzilla.redhat.com/show_bug.cgi?id=1215701

Re: iowait

2016-07-14 Thread Reindl Harald
Am 14.07.2016 um 08:08 schrieb Randeep: I am not sure whether i have to add more RAM or change the disk we are using for caching. I am using normal SATA (7k rpm) as raw disk for caching. if it's only a single disk under very high load / concurrency what do you expect? get 4 of them as

Re: Mapping rule based on cookie

2016-07-13 Thread Reindl Harald
Am 13.07.2016 um 11:37 schrieb Alex Sviridov: I need a reverse proxy which makes server mapping according to some value in cookie. For example, if there is a variable "key" and it is equal to 2 (key=2) then request must be redirected to server 100.100.100.100. Can apache traffic server do

Re: SSL termination for forward proxy?

2016-07-07 Thread Reindl Harald
Am 07.07.2016 um 13:57 schrieb Rob Maidment: I notice TS supports SSL termination in reverse proxy mode only. I would like to write a plug-in to achieve SSL termination (for HTTPS) in forward proxy mode. The plug-in would need to generate certificates on-the-fly for sites being requested,

Re: ATS guide for beginner

2016-06-14 Thread Reindl Harald
what *exactly* is your problem? https://www.digitalocean.com/community/tutorials/how-to-set-up-apache-traffic-server-as-a-reverse-proxy-on-ubuntu-14-04 just configure remap.config, point your nameserver to the ATS machine and thats's it - took 5 minutes to get the first test setup running

Re: HTTPS proxy

2016-06-06 Thread Reindl Harald
Am 06.06.2016 um 21:45 schrieb Blaxton: IS ATS only HTTP proxy , or it is HTTP/HTTPS proxy. ats perfectly supports TLS but i only can talk about a reverse-proxy and doing TLS-offloading meaning the backend connection is unencrypted and only ATS is responsible for TLS stuff Does ATS

Re: Deprecation of SSL v2/3

2016-04-25 Thread Reindl Harald
Am 26.04.2016 um 00:23 schrieb Phil Sorber: On Mon, Apr 25, 2016 at 11:01 AM Reindl Harald <h.rei...@thelounge.net as strict as the ATS configuration (see below) and so no reason for the current "ab" behavior you can verify with https://www.ssllabs.com/ssltest/ the

Re: Deprecation of SSL v2/3

2016-04-25 Thread Reindl Harald
Am 25.04.2016 um 16:10 schrieb Phil Sorber: On Mon, Apr 25, 2016, 08:05 Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>> wrote: Am 25.04.2016 um 15:54 schrieb Leif Hedstrom: >> On Apr 25, 2016, at 4:47 AM, Reindl Harald <h.rei...@thelou

Re: Deprecation of SSL v2/3

2016-04-25 Thread Reindl Harald
Am 25.04.2016 um 15:54 schrieb Leif Hedstrom: On Apr 25, 2016, at 4:47 AM, Reindl Harald <h.rei...@thelounge.net> wrote: i will give it a try ASAP, however the whole web and mail stack is built with that flags (based on the flags below which are %{optflags} and only ATS has the sp

Re: Deprecation of SSL v2/3

2016-04-25 Thread Reindl Harald
Am 25.04.2016 um 11:33 schrieb Reindl Harald: Am 17.04.2016 um 01:26 schrieb Leif Hedstrom: On Apr 16, 2016, at 4:56 PM, Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>> wrote: Am 17.04.2016 um 00:52 schrieb Leif Hedstrom: On Apr 16, 2016, at 4:44 PM, R

Re: Deprecation of SSL v2/3

2016-04-25 Thread Reindl Harald
Am 17.04.2016 um 01:26 schrieb Leif Hedstrom: On Apr 16, 2016, at 4:56 PM, Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>> wrote: Am 17.04.2016 um 00:52 schrieb Leif Hedstrom: On Apr 16, 2016, at 4:44 PM, Reindl Harald <h.rei...@thelounge.ne

Re: Deprecation of SSL v2/3

2016-04-16 Thread Reindl Harald
Am 16.04.2016 um 18:46 schrieb Phil Sorber: Ok, here is my final plan then. I am going to mark them all deprecated for 6.2.x. when you are at it fix the problem that ATS is the only TLS webserver out there which can't be benchmarked with "ab" reported by my *over years* multiple times while

Re: No caching of Octet Stream from Filehippo

2016-03-30 Thread Reindl Harald
Am 30.03.2016 um 22:13 schrieb Muhammad Faisal: The content is being cached but everytime when im attempting to download the same file the origin is responding with a different URL everytime. than there is no point to cache it - if you don't control the origin and the origin intentds not to

Re: No caching of Octet Stream from Filehippo

2016-03-30 Thread Reindl Harald
301 is a REDIRECT to debug caching issues just use "curl --head origin-url", anything else is blind guessing Am 30.03.2016 um 21:13 schrieb Muhammad Faisal: It seems the object caching is not happening even if "Last Modified" header in the origin response despite setting *CONFIG

Re: Different Cache Disk for different size of objects

2016-03-21 Thread Reindl Harald
://www.squid-cache.org/mail-archive/squid-users/201208/0284.html -- Original Message -- From: "Reindl Harald" <h.rei...@thelounge.net> To: users@trafficserver.apache.org Sent: 3/21/2016 11:21:32 PM Subject: Re: Different Cache Disk for different size of objects Am 21.03.2016

Re: Different Cache Disk for different size of objects

2016-03-21 Thread Reindl Harald
Am 21.03.2016 um 19:19 schrieb Muhammad Faisal: OK. But this feature can be added right? May be in future releases. It can improve caching performance by avoiding seek time of disks which increase over the period of time with high disk WR. but what do you are doing with a 2 GB reponse

Re: Error page when opening a site and reloads itself correctly

2016-03-19 Thread Reindl Harald
how is that a ATS problem? Am 17.03.2016 um 20:11 schrieb Muhammad Faisal: Hi, The DNS probe error appears whenever i hit a new site behind ATS and chrome reloads the page itself and site loads correctly then. Why this could be happening any clue? -- Regards, Faisal. signature.asc

Re: unsubscribe

2016-03-19 Thread Reindl Harald
who subscribed you? i guess the same person will unsubscribe you List-Unsubscribe: Am 16.03.2016 um 21:55 schrieb William Goedicke: signature.asc Description: OpenPGP digital signature

Re: Too many errors in error.log with status 502

2016-03-19 Thread Reindl Harald
Am 18.03.2016 um 06:57 schrieb Muhammad Faisal: Any update on this? that smells like your nginx is refusing the connection what about read your backends log and if that not helps provide more informations about your currecnt configuration? -- Original Message -- From: "Muhammad

Re: Limit the storage sizes for a domain or a set of domains

2016-02-21 Thread Reindl Harald
://en.wikipedia.org/wiki/Least_Recently_Used he is wrong -- Original Message -- From: "Reindl Harald" <h.rei...@thelounge.net> To: users@trafficserver.apache.org Sent: 2/20/2016 4:01:14 PM Subject: Re: Limit the storage sizes for a domain or a set of domains Am 20.02.2016

Re: Limit the storage sizes for a domain or a set of domains

2016-02-20 Thread Reindl Harald
is transparent and self managed - it don't matter who is using what amount from the cache - the only interesting question is how many cache-hits you have and hence leave the server in peace with it's LRU decisions 2016-02-19 18:58 GMT+09:00 Reindl Harald <h.rei...@thelounge.net>:

Re: Limit the storage sizes for a domain or a set of domains

2016-02-19 Thread Reindl Harald
Am 19.02.2016 um 10:06 schrieb Hiroaki Nakamura: Is there a way to limit the storage size to be used for a domain or a set of domains? For example: - example1.com: 10GB - example2.com: 20GB - example3.com + example4.com: 30GB ^ the total storage of example3.com and example4.com must be

Re: Low cache hit ratio and object caching

2016-02-04 Thread Reindl Harald
ired-headers I dont see any cache control header in the URL On 1/30/2016 6:40 AM, Reindl Harald wrote: Am 29.01.2016 um 20:46 schrieb Muhammad Faisal: sorry for being dumb but how to check the header from origin? On 1/30/2016 12:41 AM, Miles Libbey wrote: No -- from the origin. My real quest

Re: Info - traffic control

2016-02-02 Thread Reindl Harald
ty: Castle Rock Registrant State/Province: CO Registrant Postal Code: 80104 Registrant Country: US Registrant Phone: +1.6506314609 Registrant Phone Ext: Registrant Fax: +1.99 Registrant Fax Ext: Registrant Email: knutsel...@mac.com -Original Message----- From: Reindl Harald [ma

Re: Traffic_top command not found

2016-01-29 Thread Reindl Harald
4 On 1/29/2016 2:45 PM, Reindl Harald wrote: did you do anything after that hints? signature.asc Description: OpenPGP digital signature

Re: Traffic_top command not found

2016-01-29 Thread Reindl Harald
traffic_server tsxs traffic_ctl traffic_logcat traffic_sac traffic_via Please help On 1/27/2016 7:47 PM, Reindl Harald wrote: no idea, i don't package to /usr/local with "--enable-layout=Gentoo" it ends in %{_bindir}/traffic* [builduser@buildserver:~]$ cat /rpmb

Re: Low cache hit ratio and object caching

2016-01-29 Thread Reindl Harald
Am 29.01.2016 um 20:46 schrieb Muhammad Faisal: sorry for being dumb but how to check the header from origin? On 1/30/2016 12:41 AM, Miles Libbey wrote: No -- from the origin. My real question is, are you sure that url is set to be cacheable? curl --head signature.asc Description:

Re: Traffic_top command not found

2016-01-29 Thread Reindl Harald
.12-22.el6.x86_64 expat-devel-2.0.1-11.el6_2.x86_64 db4-devel-4.7.25-20.el6_7.x86_64 [root@ats ~]# On 1/29/2016 4:42 PM, Reindl Harald wrote: Am 29.01.2016 um 11:40 schrieb Muhammad Faisal: *Hi Reindl,* I recompiled the package with --disable-posix-cap and --enable-tproxy=force. Since im a bit ne

Re: Traffic_top command not found

2016-01-27 Thread Reindl Harald
Am 27.01.2016 um 13:16 schrieb Muhammad Faisal: We have recently deployed ATS 5.3.x when running traffic_top command we get error "-bash: traffic_top: command not found" deployed how? [root@proxy:~]$ which traffic_top /usr/bin/traffic_top [root@proxy:~]$ [root@proxy:~]$ rpm -q --file

Re: Traffic_top command not found

2016-01-27 Thread Reindl Harald
r}/ld.so.conf.d/* %files devel %{_bindir}/tsxs %dir %{_includedir}/trafficserver %{_includedir}/trafficserver/* %{_libdir}/%{name}/*.so %{_libdir}/%{name}/pkgconfig/*.pc %files manpages %{_mandir}/man3/* %{_docdir}/%{name}/* %files plugins %dir %{_libdir}/%{name}/plugins %{_libdir}/%{name}/plugin

Re: Traffic_top command not found

2016-01-27 Thread Reindl Harald
:/root/bin) On 1/27/2016 5:28 PM, Reindl Harald wrote: Am 27.01.2016 um 13:16 schrieb Muhammad Faisal: We have recently deployed ATS 5.3.x when running traffic_top command we get error "-bash: traffic_top: command not found" deployed how? [root@proxy:~]$ which traffic_top /usr/bin/t

Re: Too many threads

2015-12-24 Thread Reindl Harald
Am 24.12.2015 um 10:43 schrieb feng D: I found the traffic server in my machine restart too many times in one day. It will restart 40 times in one day. I then found that traffic server has too many threads. I do not know why, who can tell me. what is there many and why do you think that's

Re: Too many threads

2015-12-24 Thread Reindl Harald
18:12 GMT+08:00 Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>>: Am 24.12.2015 um 10:43 schrieb feng D: I found the traffic server in my machine restart too many times in one day. It will restart 40 times in one day.

Re: Too many threads

2015-12-24 Thread Reindl Harald
Am 24.12.2015 um 15:31 schrieb feng D: Yes, you are right. I make a lot of assumptions. I don't know how to reslove this problem. I just has the log as below. starting with assumptions but nothing about your environment will not help to solve a problem with no software FRANKLY you even

Re: Too many threads

2015-12-24 Thread Reindl Harald
a total unsupported and untested mess on your setups with parts completly outdated and others with much later generations than supported - be happy that this boots at all 2015-12-24 22:52 GMT+08:00 Reindl Harald <h.rei...@thelounge.net <mailto:h.rei...@thelounge.net>>: Am 24.1

Re: What's the common usecase of TrafficServer Cluster

2015-07-28 Thread Reindl Harald
Am 28.07.2015 um 13:22 schrieb hzwulibin: Hi, everyone Today i setup the TrafficServer cluster. However, i have some questions. How the cluster supply the service to the client, do we need other solftware like nginx or haproxy? Just want to know the most common usecase! In my thinking now, for

Re: why my data didn't cached?

2015-07-22 Thread Reindl Harald
Am 22.07.2015 um 15:31 schrieb hzwulibin: Hi, Sorry, has any log in the trafficserver can i see the response header from the origin? Here is the header catch by the tcpdump curl --head http://url/ will show the response headers [harry@rh:~]$ curl --head http://trafficserver.apache.org/

Re: [ANNOUNCE] Apache Traffic Server 5.3.1 is released!

2015-07-06 Thread Reindl Harald
thanks! TLS is fixed compared to 5.3.0 and no longer responding after testing with ssllabs (no shared ciphers error in FF), older TLS issues are still present * https://www.ssllabs.com/ssltest/ Session resumption (tickets) Yes *why* when ssl_ticket_enabled=0 in each line of

Re: [VOTE] Release Apache Traffic Server 5.3.1 (RC0)

2015-07-03 Thread Reindl Harald
hopefully TLS is working again with 5.3.1 because it was *totally* broken with 5.3.0 meaning after a ssl-test no longer responding and firefox saying no common cipher while after downgrade it works as all the months before honestly TLS offloading is the weakest part of ATS all the time :-8

  1   2   3   >