5 ms·
HAProxy 1.5 supports SSL offloading and downstream encryption
- deweller 14y agoI'm so glad to see that haproxy is finally adding native SSL support. I have used stunnel (http://www.stunnel.org/ http://www.stunnel.org/) in front of HAProxy up to now. That setup works. But I'm happy that in the future I can remove one of the moving parts from my machine and just use haproxy.
- skyebook 14y agoGreat to see another hole in secure connections being plugged.
- kennu 14y agoI wonder if it supports SNI for virtual SSL hosts?
- erichocean 14y ago+1 If it did, that'd be really, really helpful. The spec is pretty simple, I don't know why SSL implementations leave it off. :(
- daniellockard 14y agoBecause Windows XP doesn't support SNI, so not many people use it. That's my theory.
- sp332 14y agoIt does http://permalink.gmane.org/gmane.comp.web.haproxy/8134 http://permalink.gmane.org/gmane.comp.web.haproxy/8134 Last I heard, it was buggy unless you used a specific build from April http://blog.exceliance.fr/2012/04/13/enhanced-ssl-load-balancing-with-server-name-indication-sni-tls-extension/ http://blog.exceliance.fr/2012/04/13/enhanced-ssl-load-balan... but it may have improved since.
- bsenftner 14y agoThis is great, exactly when I need it.
- bastichelaar 14y agoWhat I would like to see is a way to change the HAProxy configuration on the fly, or something like a configuration backend. That would avoid reloading HAProxy after each config change, and allow a much more flexible configuration.
- cdavid 14y agoWhy is haproxy reloading an issue ? It works pretty well in my experience (although I am not in the web business anymore, so things may have changed in the last two years).
- bastichelaar 14y agoReloading is no issue when you have few frontends or backends. But when you have a lot of front- or backends, the configuration file will be huge, and reloading will take some time. If you need to reload every few seconds, this might even cause downtime. But I guess our workload is not the usual implementation of HAProxy...
- mcguire 14y ago"But when you have a lot of front- or backends, the configuration file will be huge, and reloading will take some time. If you need to reload every few seconds..." Uh, yeah, I suspect your workload is unusual.
- wensheng 14y agoI can not build it in Fedora (both 12 and 16). Ubuntu is fine. "include/proto/proto_http.h" defined "error_message", this is in conflict with the "error_message" already defined in "et/com_err.h", which is included by "krb5/krb5.h", which itself is included by "openssl/kssl.h", which included by "openssl/ssl.h" Where do I submit a bug report? Couldn't find the link on haproxy site.
- ibotty 14y agojust use the software-engineering 2.0 way (vc but not github) and send a mail to their mailing list: haproxy@formilux.org
- StavrosK 14y agoCan anyone tell me how HAProxy compares to Varnish? I've used the latter and swear by it, but I've never used HAProxy. Is it as amazingly fast at caching as Varnish is? Right now I do nginx (for SSL) -> Varnish (caching) -> nginx (static media/proxying) -> gunicorn (Django). I'd love to remove many of those parts.
- wmf 14y agoLast I heard, HAProxy does not perform any caching. I agree that fewer components in the stack would be an improvement, but we seem to be in the minority.
- ibotty 14y agoyou are part of a vocal minority. there is a reason though for the unixy model of operation with more (well-defined as proxys usually are) smaller components.
- ibotty 14y agosee the official haproxy blog about it: [1] and [2]. i think it's a valid comparison. but as i said in my submission of the first of these articles, there are some (minor) mistakes. [1] http://blog.exceliance.fr/2012/07/04/haproxy-and-varnish-comparison http://blog.exceliance.fr/2012/07/04/haproxy-and-varnish-com... [2] http://blog.exceliance.fr/2012/08/25/haproxy-varnish-and-the-single-hostname-website/ http://blog.exceliance.fr/2012/08/25/haproxy-varnish-and-the... [3] https://news.ycombinator.com/item?id=4198339 https://news.ycombinator.com/item?id=4198339