3 ms·
This is absurd. You don't need to make certs for SSL sites, you can proxy SNI without every touching the real connection. HAProxy handles this well: https://www
by rguiliani 10y ago
This is absurd. You don't need to make certs for SSL sites, you can proxy SNI without every touching the real connection. HAProxy handles this well: https://www.haproxy.com/doc/aloha/7.0/deployment_guides/tls_layouts.html https://www.haproxy.com/doc/aloha/7.0/deployment_guides/tls_...
This is a horrible practice. BAD BAD BAD. No one cares about your terms of service, you need to rewrite that shit.
- etienne_cf 10y ago> you can proxy SNI without every touching the real connection. HAProxy handles this well. I guess you're thinking of the paragraph "SSL/TLS passthrough" described in the webpage above. Unfortunately, that doesn't work with either a CDN or a DDoS protection service, because it's simply forwarding the whole traffic to the origin: In that scenario, you can't cache assets at the CDN edge or detect layer 7 attacks.