Quantcast
Channel: HAProxy community - Latest topics
Viewing all articles
Browse latest Browse all 4731

Seamless reloads: SSL handshake failures

$
0
0

@happy wrote:

Apache benchmark shows a lot of SSL failures during reloads. Failures appear after a reload is finished.

Possibly, it is not a problem, because conditions are very specific and the same shows also qdisc-method.

SSL handshake failed (5).
SSL handshake failed (5).
SSL handshake failed (5).
SSL read failed (1) - closing connection
139687255426944:error:140E0197:SSL routines:SSL_shutdown:shutdown while in init:…/ssl/ssl_lib.c:1735:

Conditions:

  • Debian 8 x64, 4.9, systemd + HA-Proxy version 1.8.3-a91f55-27 (USE_GETADDRINFO=1 USE_ZLIB=1 USE_REGPARM=1 USE_OPENSSL=1 USE_LUA=1 USE_SYSTEMD=1 USE_PCRE=1 USE_PCRE_JIT=1 USE_TFO=1 USE_NS=1)
  • 30 test-threads + extremely low-end CPU + RSA-4096 to make it slow (about 25 requests \ sec, request time 1-1.5 sec)
  • Very large cfg-file with a lot of backends and big lua-includes

Posts: 1

Participants: 1

Read full topic


Viewing all articles
Browse latest Browse all 4731

Trending Articles