This is a discussion on [stunnel-users] performance configuration for rehl3 & JBoss within the Stunnel Users forums, part of the Networking and Network Related category; This is a multi-part message in MIME format. --===============1068675988== Content-class: urn:content-classes:message Content-Type: multipart/alternative; ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
This is a multi-part message in MIME format.
--===============1068675988== Content-class: urn:content-classes:message Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C71594.6393FE42" This is a multi-part message in MIME format. ------_=_NextPart_001_01C71594.6393FE42 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable I am having problems will apache and stunnel being able to handle load. I am using stunnel to encrypt my ajp traffic from apache to jboss. This helps me bridge our internal firewall. =20 But during load testing the system starts breaking down. It takes about 1/5 the load to break down apache and stunnel, than directly against my jboss node. =20 Any performance tuning recommendations would be great. I am using stunnel straight out of the box. I will place the configuration file below. =20 Thanks. =20 ; Sample stunnel configuration file by Michal Trojnara 2002-2006 ; Some options used here may not be adequate for your particular configuration ; Please make sure you understand them (especially the effect of chroot jail) =20 ; Certificate/key is needed in server mode and optional in client mode ;cert =3D /usr/local/stunnel/etc/stunnel/mail.pem ;key =3D /usr/local/stunnel/etc/stunnel/mail.pem =20 ; Protocol version (all, SSLv2, SSLv3, TLSv1) sslVersion =3D SSLv3 =20 ; Some security enhancements for UNIX systems - comment them out on Win32 chroot =3D /usr/local/stunnel/var/lib/stunnel/ setuid =3D nobody setgid =3D nogroup ; PID is created inside chroot jail pid =3D /stunnel.pid =20 ; Some performance tunings socket =3D l:TCP_NODELAY=3D1 socket =3D r:TCP_NODELAY=3D1 ;compression =3D rle =20 ; Workaround for Eudora bug ;options =3D DONT_INSERT_EMPTY_FRAGMENTS =20 ; Authentication stuff ;verify =3D 2 ; Don't forget to c_rehash CApath ; CApath is located inside chroot jail CApath =3D certificates ; It's often easier to use CAfile CAfile =3D /usr/local/stunnel/etc/stunnel/certs.pem ; Don't forget to c_rehash CRLpath ; CRLpath is located inside chroot jail ;CRLpath =3D /crls ; Alternatively you can use CRLfile ;CRLfile =3D /usr/local/stunnel/etc/stunnel/crls.pem =20 ; Some debugging stuff useful for troubleshooting ;debug =3D 7 output =3D stunnel.log =20 ; Use it for client mode client =3D yes =20 ; Service-level configuration =20 [ajp] accept =3D 8009 connect =3D xxxx2:8009 =20 [sql] accept =3D 1433 connect =3D XXXX1:443 ************************************************** *********************** The information contained in this communication is confidential, is intended only for the use of the recipient named above, and may be legally privileged. If the reader of this message is not the intended recipient, you are=20 hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please resend this communication to the sender and delete the original message or any copy of it from your computer system. Thank you. ************************************************** *********************** ------_=_NextPart_001_01C71594.6393FE42 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc= hemas-microsoft-com:office:word" xmlns=3D"http://www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii"> <meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)"> <style> <!-- /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman";} a:link, span.MsoHyperlink {color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {color:purple; text-decoration:underline;} span.EmailStyle18 {mso-style-type:personal-compose; font-family:Arial; color:windowtext;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.25in 1.0in 1.25in;} div.Section1 {page:Section1;} --> </style> </head> <body lang=3DEN-US link=3Dblue vlink=3Dpurple> <div class=3DSection1> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>I am having problems will apache and stunnel being able = to handle load. I am using stunnel to encrypt my ajp traffic from apache= to jboss. This helps me bridge our internal firewall.<o:p></o:p></span><= /font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>But during load testing the system starts breaking down.= It takes about 1/5 the load to break down apache and stunnel, than directly against my jboss node.<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>Any performance tuning recommendations would be great.<o= :p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>I am using stunnel straight out of the box. I will place the configuration file below.<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <div style=3D'mso-element:para-border-div;border:none;border-bottom:dotted = windowtext 3.0pt; padding:0in 0in 1.0pt 0in'> <p class=3DMsoNormal style=3D'border:none;padding:0in'><font size=3D2 face= =3DArial><span style=3D'font-size:10.0pt;font-family:Arial'>Thanks.<o:p></o:p></span></fon= t></p> </div> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Sample stunnel configuration file by Michal Trojnara 2002-2006<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Some options used here may not be adequate for your particular configuration<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Please make sure you understand them (especially the effect of chroot jail)<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Certificate/key is needed in server mode and optional = in client mode<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>;cert =3D /usr/local/stunnel/etc/stunnel/mail.pem<o:p></= o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>;key =3D /usr/local/stunnel/etc/stunnel/mail.pem<o:p></o= :p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Protocol version (all, SSLv2, SSLv3, TLSv1)<o:p></o:p>= </span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>sslVersion =3D SSLv3<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Some security enhancements for UNIX systems - comment = them out on Win32<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>chroot =3D /usr/local/stunnel/var/lib/stunnel/<o:p></o:p= ></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>setuid =3D nobody<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>setgid =3D nogroup<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; PID is created inside chroot jail<o:p></o:p></span></f= ont></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>pid =3D /stunnel.pid<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Some performance tunings<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>socket =3D l:TCP_NODELAY=3D1<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>socket =3D r:TCP_NODELAY=3D1<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>;compression =3D rle<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Workaround for Eudora bug<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>;options =3D DONT_INSERT_EMPTY_FRAGMENTS<o:p></o:p></spa= n></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Authentication stuff<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>;verify =3D 2<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Don't forget to c_rehash CApath<o:p></o:p></span></fon= t></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; CApath is located inside chroot jail<o:p></o:p></span>= </font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>CApath =3D certificates<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; It's often easier to use CAfile<o:p></o:p></span></fon= t></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>CAfile =3D /usr/local/stunnel/etc/stunnel/certs.pem<o:p>= </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Don't forget to c_rehash CRLpath<o:p></o:p></span></fo= nt></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; CRLpath is located inside chroot jail<o:p></o:p></span= ></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>;CRLpath =3D /crls<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Alternatively you can use CRLfile<o:p></o:p></span></f= ont></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>;CRLfile =3D /usr/local/stunnel/etc/stunnel/crls.pem<o:p= ></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Some debugging stuff useful for troubleshooting<o:p></= o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>;debug =3D 7<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>output =3D stunnel.log<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Use it for client mode<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>client =3D yes<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>; Service-level configuration<o:p></o:p></span></font></= p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>[ajp]<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>accept =3D 8009<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>connect =3D xxxx2:8009<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>[sql]<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>accept =3D 1433<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1= 0=2E0pt; font-family:Arial'>connect =3D XXXX1:443<o:p></o:p></span></font></p> </div> <pre>********************************************* *************************= *** The information contained in this communication is confidential, is intended only for the use of the recipient named above, and may be legally privileged. If the reader of this message is not the intended recipient, you are=20 hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please resend this communication to the sender and delete the original message or any copy of it from your computer system. Thank you. ************************************************** *********************** </pre></body> </html> ------_=_NextPart_001_01C71594.6393FE42-- --===============1068675988== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ stunnel-users mailing list stunnel-users@mirt.net http://stunnel.mirt.net/mailman/listinfo/stunnel-users --===============1068675988==-- |
![]() |
| Thread Tools | |
| Display Modes | |
|
|