[stunnel-users] Using stunnel + haproxy for SSL support

This is a discussion on [stunnel-users] Using stunnel + haproxy for SSL support within the Stunnel Users forums, part of the Networking and Network Related category; Hi, I'm having trouble using stunnel and haproxy to load balance https and http traffic. To be honest, I ...


Go Back   Usenet Forums > Networking and Network Related > Stunnel Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 04-04-2008
Alberto Giménez
 
Posts: n/a
Default [stunnel-users] Using stunnel + haproxy for SSL support

Hi,

I'm having trouble using stunnel and haproxy to load balance https and
http traffic. To be honest, I really don't know wether it is stunnel
or haproxy related so I am going to contact both lists :)

I have set up a haproxy load balancer as http proxy for two backend
Apache2 webservers. It works fine.
I also have stunnel on the same LB to add SSL suport (with
xforwardedfor patch installed). It works fine (mostly).

The issue is related to Apache trailing slash thingie. If I query
https://haproxy.domain.loc/hatest/ it works perfectly, but if I omit
the trailing slash: https://haproxy.domain.loc/hatest then following
things happen:

- Browser makes SSL connection with stunnel on port 443.
- stunnel deciphers and forwards the request on the haproxy attached
to LB's port 80.
- haproxy (now using plain http) forwards to one of the backends.
- Apache2 located on the backend replies with "301 moved permanently"
to force the browser to add the trailing slash. As Apache was queried
by *haproxy in plain http*, the 301 includes http:// on the Location
header. HTTPS is over from now!
- The client browser then rewrites the address to
http://haproxy.domain.loc/hatest/ and SSL is lost forever.

I've been googling and searching the lists but nothing found, just
this old message:

http://mirt.net/pipermail/stunnel-us...ry/001437.html

Has anyone found a workaround for that issue?

Thanks in advance.


-- =

Alberto Gim=E9nez
_______________________________________________
stunnel-users mailing list
stunnel-users@mirt.net
http://stunnel.mirt.net/mailman/listinfo/stunnel-users
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:11 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0