4 ms·
Cloudflare Enables HTTPS TLS 1.3 Backend Origin Communication
- cuu508 8y agoI'm running Ubuntu 18.04 LTS. It comes with nginx 1.14.0 (good) and OpenSSL 1.1.0g (too old, need at least 1.1.1 for TLS 1.3 to work). Apparently there are plans to backport OpenSSL 1.1.1: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1797386 https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/17973... I'd rather not install 3rd party nginx & OpenSSL builds, or compile it myself, so I'll just wait for the backport and test then.
- vbtechguy 8y agoYeah you're at the mercy of what version of OpenSSL is used by your Nginx binaries. I always like to play with bleeding edge latest tech so TLS 1.3 is a must for me, so I always build my Centmin Mod Nginx binaries using Nginx mainline 1.15 branch with end user selectable choice of OpenSSL 1.1.1 branch or BoringSSL crypto libraries - both allow my Nginx binaries to support TLS 1.3 https://community.centminmod.com/threads/centmin-mod-nginx-http-2-https-tls-1-3-support.15537/ https://community.centminmod.com/threads/centmin-mod-nginx-h... :)
- bashy 8y agoAny real reason for not using 3rd party? Could use ppa:ondrej/nginx and install OpenSSL 1.1.1b along with nginx.
- cuu508 8y agoMust vet the 3rd party (Trustworthy? Likely to stick around and have timely security updates?). Must do testing with my setup – nginx is not the only thing that's using OpenSSL on the server. I would test the official backport as well, but it would likely have more users and so more issues already taken care of. And TLS 1.3 is not yet a must-have requirement for me.
- bashy 8y agoYeah understandable. FYI, they're a main player in the package world https://launchpad.net/~ondrej https://launchpad.net/~ondrej Debian Buster is OpenSSL 1.1.1a so that's good.
- hannob 8y agoYour comment kinda embodies everything that is complicated about Linux distribution support. You use an LTS distribution, yet you want to have bleeding edge features. It sounds like you simply want two things that are in contradiction to each other.
- vbtechguy 8y agoYeah LTS or bleeding edge is always time relative. For example OpenSSL 1.1.1 is the new LTS release https://www.openssl.org/blog/blog/2018/09/11/release111/ https://www.openssl.org/blog/blog/2018/09/11/release111/ > After two years of work we are excited to be releasing our latest version today - OpenSSL 1.1.1. This is also our new Long Term Support (LTS) version and so we are committing to support it for at least five years.
- sneak 8y agoWhat does “support” in “long term support” mean if not “support the current stable version of the most widely used cryptosystem on the planet”? I think the arbitrary distinction of “point releases can include x but not y” where x is bugfixes related to security and stability and y is bugfixes in a protocol means that there is not a contradiction there.
- cesarb 8y ago> What does “support” in “long term support” mean if not “support the current stable version of the most widely used cryptosystem on the planet”? It means "support whatever was included in the distribution for a long time". That is, what matters is the "current stable version" at the moment the distribution was originally released. > where x is bugfixes related to security and stability and y is bugfixes in a protocol means that there is not a contradiction there. TLS 1.3 is a new protocol, not a bugfix. A bugfix to the protocol would be something like the renegotiation extension (RFC 5746).
- sneak 8y ago> It means "support whatever was included in the distribution for a long time". The TLS protocol was included in the distribution. (You seem to be using a self-recursive definition of “support”.)
- kim0 8y agoMaybe docker would help
- FBISurveillance 8y agoWhile nginx is a great piece of software, I've found that envoy is marching forward at much greater pace with support for HTTP/2 upstream, grpc, tls 1.3, active healthchecks, upstream dns resolution, and many other features. Not to mention it's fully open source and does not have "open core" problems that I feel like partially account to nginx lagging behind in some areas.
- tux1968 8y agoWell he is using Nginx as a web server, not just a proxy. At least that my guess based on the context.
- vbtechguy 8y agoyes I am using Nginx as a primary web server which is behind Cloudflare using Cloudflare Strict SSL - hence glad to see Cloudflare communicate with my origin via TLS 1.3
- tobbyb 8y agoThis is where containers can help. Ubuntu ships with LXC and its relatively simple to download an Alpine Linux container and then install Nginx and you are set. Alternatively Flockport [self plug] provides an open source app store [1] for LXC and you can download a prebuilt Nginx114 container all set to go. But containers are some work with both upsides and downsides and upsides compared to having it out of the box in the distribution. [1] https://www.flockport.com/apps https://www.flockport.com/apps
- js2 8y agoMaybe as a compromise, consider running the nginx docker image built by nginx.com.
- vbtechguy 8y agoi believe those are build against non-OpenSSL 1.1.1 branch so don't have TLS 1.3 supported by official nginx docker images.
- tialaramex 8y agoInterestingly they've chosen to just not offer 0RTT at all at the back end, at least for now. I'm not actually sure if this helps. I guess it means 0RTT mitigation at Cloudflare concentrates the risk there - they can take full responsibility for doing a good job and if your clients have nasty RTT (e.g. satellite) you get most of the benefit with no work. Still, if you're very small 0RTT safety is easy whereas Cloudflare has to work very hard to even make it somewhat resist replays because their system is so distributed.
- vbtechguy 8y agoYeah confirmed no TLS 1.3 0-RTT early data support on origin backend communications right now https://community.cloudflare.com/t/cloudflare-speak-tls-1-3-0-rtt-with-origin-backend/31507 https://community.cloudflare.com/t/cloudflare-speak-tls-1-3-...
- toast0 8y agoThey're not going to proxy the 0RTT to the origin to determine if they accept it or not, so it's two separate questions of accepting it from clients and offering it to origins. For clients, especially mobile or satellite clients, the latency win from one round trip saved may be worth the risk; for origins, the worst latency is probably not too much, and connection reuse over multiple client requests likely reduces the total number of connections made.
- dward 8y agoThe policy seems sane. * They know when they can serve 0RTT from their cache safely because they can be reasonably certain if handling a cached request is side effect free. * If connections to backend origins are reasonably persistent, there's not much latency reduction benefit from 0RTT compared to connections from consumer user agents.
- mobilemidget 8y agoCentmin website can really use a easy to find “what is centmin?” section.
- vbtechguy 8y agoit's on the very first sentence on the site (not the forums) https://centminmod.com/ https://centminmod.com/ linking to https://centminmod.com/lemp.html https://centminmod.com/lemp.html
- mobilemidget 8y agothat was not the site linked, and took me a lot of clicking to finally see yes. though having read up quite a bit, not really a big fan.