William Lallemand

30 Followers
71 Following
46 Posts
@kalfeher obsolete protocols and softwares are part of a lot of ecosystem. Unfortunately deprecating something doesn't make it disappear, but rest assured, TLSv1.0 and 1.1 are disabled by default. Like we said in the article, that's to "accommodate diverse client requirements while encouraging migration to more secure protocols.". Most openssl drop-in replacement still implements TLS1.0, so that's not really an important point. It's not about designing a software, switching this on is basically 2 lines of code.
The State of SSL Stacks

The SSL landscape has shifted dramatically. In this paper, we examine OpenSSL 3.x, BoringSSL, LibreSSL, WolfSSL, and AWS-LC with HAProxy.

HAProxy Technologies
@kalfeher
Hopefully TLS 1.0 will disappear, but there are still cases where people want to use a modern HAProxy stack in front of a proprietary software which only handles TLS 1.0 for example. HAProxy is a swiss army knife which handles that kind of cases, and make people life easy in hostile environment 🙂
@mirabilos We consider that LibreSSL is a really good implementation for small use-cases, but it wasn't performant enough nor complete enough to be considered as a replacement of OpenSSL for most haproxy users. However we will still support this library and will be happy to improve its support within haproxy.
Welcome back to our friends @HAProxy as @netdevconf 0x19 silver sponsor
@HAProxy is the world’s fastest and most widely used software load balancer! Thank you for your continued support! #netdevconf
#HAProxy

Alpine Linux needs your help, a significant sponsorship will end soon.

This post explains what is affected and how you can help:

https://alpinelinux.org/posts/Seeking-Support-After-Equinix-Metal-Sunsets.html

#AlpineLinux

Seeking Support After Equinix Metal Sunsets | Alpine Linux

Alpine Linux

@bug Maybe you should try to write this with c++ templates, you could have more luck.
@tekkie I agree that's not super easy, but it's planned to have it integrated within haproxy. using acme.sh with this procedure allows you to do it without reloading the haproxy process, but you could do it with anything else like certbot and reloading. Don't hesitate to give me feedback about what you need or expect from this feature!
[ANNOUNCE] haproxy-3.1.0

[ANNOUNCE] haproxy-3.0.0