[stunnel-users] performance configuration for rehl3 & JBoss

This is a discussion on [stunnel-users] performance configuration for rehl3 & JBoss within the Stunnel Users forums, part of the Networking and Network Related category; This is a multi-part message in MIME format. --===============1068675988== Content-class: urn:content-classes:message Content-Type: multipart/alternative; ...


Go Back   Usenet Forums > Networking and Network Related > Stunnel Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-01-2006
Jones Scott - sjones
 
Posts: n/a
Default [stunnel-users] performance configuration for rehl3 & JBoss

This is a multi-part message in MIME format.

--===============1068675988==
Content-class: urn:content-classes:message
Content-Type: multipart/alternative;
boundary="----_=_NextPart_001_01C71594.6393FE42"

This is a multi-part message in MIME format.

------_=_NextPart_001_01C71594.6393FE42
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

I am having problems will apache and stunnel being able to handle load.
I am using stunnel to encrypt my ajp traffic from apache to jboss. This
helps me bridge our internal firewall.

=20

But during load testing the system starts breaking down. It takes about
1/5 the load to break down apache and stunnel, than directly against my
jboss node.

=20

Any performance tuning recommendations would be great.

I am using stunnel straight out of the box. I will place the
configuration file below.

=20

Thanks.

=20

; Sample stunnel configuration file by Michal Trojnara 2002-2006

; Some options used here may not be adequate for your particular
configuration

; Please make sure you understand them (especially the effect of chroot
jail)

=20

; Certificate/key is needed in server mode and optional in client mode

;cert =3D /usr/local/stunnel/etc/stunnel/mail.pem

;key =3D /usr/local/stunnel/etc/stunnel/mail.pem

=20

; Protocol version (all, SSLv2, SSLv3, TLSv1)

sslVersion =3D SSLv3

=20

; Some security enhancements for UNIX systems - comment them out on
Win32

chroot =3D /usr/local/stunnel/var/lib/stunnel/

setuid =3D nobody

setgid =3D nogroup

; PID is created inside chroot jail

pid =3D /stunnel.pid

=20

; Some performance tunings

socket =3D l:TCP_NODELAY=3D1

socket =3D r:TCP_NODELAY=3D1

;compression =3D rle

=20

; Workaround for Eudora bug

;options =3D DONT_INSERT_EMPTY_FRAGMENTS

=20

; Authentication stuff

;verify =3D 2

; Don't forget to c_rehash CApath

; CApath is located inside chroot jail

CApath =3D certificates

; It's often easier to use CAfile

CAfile =3D /usr/local/stunnel/etc/stunnel/certs.pem

; Don't forget to c_rehash CRLpath

; CRLpath is located inside chroot jail

;CRLpath =3D /crls

; Alternatively you can use CRLfile

;CRLfile =3D /usr/local/stunnel/etc/stunnel/crls.pem

=20

; Some debugging stuff useful for troubleshooting

;debug =3D 7

output =3D stunnel.log

=20

; Use it for client mode

client =3D yes

=20

; Service-level configuration

=20

[ajp]

accept =3D 8009

connect =3D xxxx2:8009

=20

[sql]

accept =3D 1433

connect =3D XXXX1:443

************************************************** ***********************
The information contained in this communication is confidential, is
intended only for the use of the recipient named above, and may be
legally privileged.

If the reader of this message is not the intended recipient, you are=20
hereby notified that any dissemination, distribution or copying of this
communication is strictly prohibited.

If you have received this communication in error, please resend this
communication to the sender and delete the original message or any copy
of it from your computer system.

Thank you.
************************************************** ***********************

------_=_NextPart_001_01C71594.6393FE42
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<style>
<!--
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman";}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
span.EmailStyle18
{mso-style-type:personal-compose;
font-family:Arial;
color:windowtext;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
{page:Section1;}
-->
</style>

</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>I am having problems will apache and stunnel being able =
to
handle load. &nbsp;I am using stunnel to encrypt my ajp traffic from apache=
to
jboss. &nbsp;This helps me bridge our internal firewall.<o:p></o:p></span><=
/font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>But during load testing the system starts breaking down.=
&nbsp;It
takes about 1/5 the load to break down apache and stunnel, than directly
against my jboss node.<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>Any performance tuning recommendations would be great.<o=
:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>I am using stunnel straight out of the box. &nbsp;I will
place the configuration file below.<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<div style=3D'mso-element:para-border-div;border:none;border-bottom:dotted =
windowtext 3.0pt;
padding:0in 0in 1.0pt 0in'>

<p class=3DMsoNormal style=3D'border:none;padding:0in'><font size=3D2 face=
=3DArial><span
style=3D'font-size:10.0pt;font-family:Arial'>Thanks.<o:p></o:p></span></fon=
t></p>

</div>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Sample stunnel configuration file by Michal Trojnara
2002-2006<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Some options used here may not be adequate for your
particular configuration<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Please make sure you understand them (especially the
effect of chroot jail)<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Certificate/key is needed in server mode and optional =
in
client mode<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>;cert =3D /usr/local/stunnel/etc/stunnel/mail.pem<o:p></=
o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>;key =3D /usr/local/stunnel/etc/stunnel/mail.pem<o:p></o=
:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Protocol version (all, SSLv2, SSLv3, TLSv1)<o:p></o:p>=
</span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>sslVersion =3D SSLv3<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Some security enhancements for UNIX systems - comment =
them
out on Win32<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>chroot =3D /usr/local/stunnel/var/lib/stunnel/<o:p></o:p=
></span></font></p>


<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>setuid =3D nobody<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>setgid =3D nogroup<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; PID is created inside chroot jail<o:p></o:p></span></f=
ont></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>pid =3D /stunnel.pid<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Some performance tunings<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>socket =3D l:TCP_NODELAY=3D1<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>socket =3D r:TCP_NODELAY=3D1<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>;compression =3D rle<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Workaround for Eudora bug<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>;options =3D DONT_INSERT_EMPTY_FRAGMENTS<o:p></o:p></spa=
n></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Authentication stuff<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>;verify =3D 2<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Don't forget to c_rehash CApath<o:p></o:p></span></fon=
t></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; CApath is located inside chroot jail<o:p></o:p></span>=
</font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>CApath =3D certificates<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; It's often easier to use CAfile<o:p></o:p></span></fon=
t></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>CAfile =3D /usr/local/stunnel/etc/stunnel/certs.pem<o:p>=
</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Don't forget to c_rehash CRLpath<o:p></o:p></span></fo=
nt></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; CRLpath is located inside chroot jail<o:p></o:p></span=
></font></p>


<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>;CRLpath =3D /crls<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Alternatively you can use CRLfile<o:p></o:p></span></f=
ont></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>;CRLfile =3D /usr/local/stunnel/etc/stunnel/crls.pem<o:p=
></o:p></span></font></p>


<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Some debugging stuff useful for troubleshooting<o:p></=
o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>;debug =3D 7<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>output =3D stunnel.log<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Use it for client mode<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>client =3D yes<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>; Service-level configuration<o:p></o:p></span></font></=
p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>[ajp]<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>accept =3D 8009<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>connect =3D xxxx2:8009<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>[sql]<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>accept =3D 1433<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span style=3D'font-size:1=
0=2E0pt;
font-family:Arial'>connect =3D XXXX1:443<o:p></o:p></span></font></p>

</div>

<pre>********************************************* *************************=
***
The information contained in this communication is confidential, is
intended only for the use of the recipient named above, and may be
legally privileged.

If the reader of this message is not the intended recipient, you are=20
hereby notified that any dissemination, distribution or copying of this
communication is strictly prohibited.

If you have received this communication in error, please resend this
communication to the sender and delete the original message or any copy
of it from your computer system.

Thank you.
************************************************** ***********************
</pre></body>

</html>

------_=_NextPart_001_01C71594.6393FE42--

--===============1068675988==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
stunnel-users mailing list
stunnel-users@mirt.net
http://stunnel.mirt.net/mailman/listinfo/stunnel-users

--===============1068675988==--
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 12:32 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0