DevHeads.net

SSL-Settings for Healthchecks (mod_proxy_balancer)

Hello all apache-users!
I'm trying to set up load-balancing to backends which use different SSL/TLS settings.
I'm using version 2.4.33 of apache.
According to documentation it should be possible to set SSLProxy* directives inside a <Proxy> section. I'm trying to do something like this :

<VHost>
SSLProxyEngine on
<Proxy balancer://mybalancer >
SSLProxyProtocol TLSv1.2
SSLProxyCipherSuite ....
(other SSLProxy* directives like SSLProxyCAFile etc.)
BalancerMember 1.....
BalacnerMember 2.....
</Proxy>
<VHost>

In the above example, the healthchecks use the standard SSL-settings defined in global scope, not the ones defined inside the Proxy section
The idea behind that is, that i want to set different TLS-settings (for healthchecks) on different LoadBalancers. When i move the directives up (on VHost level), the healthchecks take that into account, but like this, i cannot create more then one balancer inside a vhost...

If also asked this question on stackoverflow :

<a href="https://stackoverflow.com/questions/51261409/apache-loadbalancing-ssl-tls-settings-for-healthchecks" title="https://stackoverflow.com/questions/51261409/apache-loadbalancing-ssl-tls-settings-for-healthchecks">https://stackoverflow.com/questions/51261409/apache-loadbalancing-ssl-tl...</a>

Any suggestions welcome.
Cheers
Dominik

Comments

Re: SSL-Settings for Healthchecks (mod_proxy_balan

By Yann Ylavic at 07/10/2018 - 11:31

Hi Dominik,

On Tue, Jul 10, 2018 at 1:03 PM, Dominik Stillhard
<Dominik.Stillhard@united-security-providers.ch> wrote:
It seems that the merging between the Balancer and VHost does not
happen in mod_proxy_hcheck (health check).
Can you test patches?

Regards,
Yann.

Re: SSL-Settings for Healthchecks (mod_proxy_balan

By Yann Ylavic at 07/10/2018 - 11:44

On Tue, Jul 10, 2018 at 5:31 PM, Yann Ylavic <ylavic. ... at gmail dot com> wrote:
If so, something like the attached patch might work (untested on my side).

AW: [users@httpd] SSL-Settings for Healthchecks (mod_proxy_balan

By Dominik Stillhard at 07/11/2018 - 02:47

Thanks! I will test the patch!