22< html lang ="en ">
33 < head >
44 < meta charset ="utf-8 " />
5- < title > HAProxy version 3.2-dev1-22 - Management Guide</ title >
5+ < title > HAProxy version 3.2-dev1-32 - Management Guide</ title >
66 < link href ="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/css/bootstrap.min.css " rel ="stylesheet " />
77 < link href ="https://raw.githubusercontent.com/thomaspark/bootswatch/v3.3.7/cerulean/bootstrap.min.css " rel ="stylesheet " />
88 < link href ="../css/page.css?0.4.2-15 " rel ="stylesheet " />
654654 You can use < strong > left</ strong > and < strong > right</ strong > arrow keys to navigate between chapters.< br >
655655 </ p >
656656 < p class ="text-right ">
657- < small > Converted with < a href ="https://github.com/cbonte/haproxy-dconv "> haproxy-dconv</ a > v< b > 0.4.2-15</ b > on < b > 2024/12/12 </ b > </ small >
657+ < small > Converted with < a href ="https://github.com/cbonte/haproxy-dconv "> haproxy-dconv</ a > v< b > 0.4.2-15</ b > on < b > 2024/12/16 </ b > </ small >
658658 </ p >
659659 </ div >
660660 <!-- /.sidebar -->
665665 < div class ="text-center ">
666666 < h1 > < a href ="http://www.haproxy.org/ " title ="HAProxy "> < img src ="../img/HAProxyCommunityEdition_60px.png?0.4.2-15 " /> </ a > </ h1 >
667667 < h2 > Management Guide</ h2 >
668- < p > < strong > version 3.2-dev1-22 </ strong > </ p >
668+ < p > < strong > version 3.2-dev1-32 </ strong > </ p >
669669 < p >
670670 < br >
671671
@@ -4136,7 +4136,7 @@ <h2 id="chapter-9.3" data-target="9.3"><small><a class="small" href="#9.3">9.3.<
41364136
41374137$ echo "show stat json" | socat /var/run/haproxy.sock stdio | \
41384138 python -m json.tool
4139- </ pre > < a class ="anchor " name ="show "> </ a > < a class ="anchor " name ="9-show "> </ a > < a class ="anchor " name ="9.3-show "> </ a > < a class ="anchor " name ="show (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl "> </ a > < a class ="anchor " name ="9-show ssl "> </ a > < a class ="anchor " name ="9.3-show ssl "> </ a > < a class ="anchor " name ="show ssl (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl ca-file "> </ a > < a class ="anchor " name ="9-show ssl ca-file "> </ a > < a class ="anchor " name ="9.3-show ssl ca-file "> </ a > < a class ="anchor " name ="show ssl ca-file (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl ca-file (Unix Socket commands) "> </ a > < div class ="keyword "> < b > < a class ="anchor " name ="show ssl ca-file "> </ a > < a href ="#9.3-show%20ssl%20ca-file "> show ssl ca-file</ a > </ b > < span style ="color: #008 "> [< span style ="color: #080 "> <cafile></ span > < span style ="color: #008 "> [:< span style ="color: #080 "> <index></ span > ]</ span > ]</ span > </ div > < pre class ="text "> Display the list of CA files loaded into the process and their respective
4139+ </ pre > < a class ="anchor " name ="show "> </ a > < a class ="anchor " name ="9-show "> </ a > < a class ="anchor " name ="9.3-show "> </ a > < a class ="anchor " name ="show (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl "> </ a > < a class ="anchor " name ="9-show ssl "> </ a > < a class ="anchor " name ="9.3-show ssl "> </ a > < a class ="anchor " name ="show ssl (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl ca-file "> </ a > < a class ="anchor " name ="9-show ssl ca-file "> </ a > < a class ="anchor " name ="9.3-show ssl ca-file "> </ a > < a class ="anchor " name ="show ssl ca-file (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl ca-file (Unix Socket commands) "> </ a > < div class ="keyword "> < b > < a class ="anchor " name ="show ssl ca-file "> </ a > < a href ="#9.3-show%20ssl%20ca-file "> show ssl ca-file</ a > </ b > < span style ="color: #008 "> [< span style ="color: #008 "> [*]</ span > < span style ="color: #008 "> [\]</ span > < span style ="color: #080 "> <cafile></ span > < span style ="color: #008 "> [:< span style ="color: #080 "> <index></ span > ]</ span > ]</ span > </ div > < pre class ="text "> Display the list of CA files loaded into the process and their respective
41404140certificate counts. The certificates are not used by any frontend or backend
41414141until their status is "Used".
41424142A "@system-ca" entry can appear in the list, it is loaded by the httpclient
@@ -4152,7 +4152,8 @@ <h2 id="chapter-9.3" data-target="9.3"><small><a class="small" href="#9.3">9.3.<
41524152If the index is invalid (too big for instance), nothing will be displayed.
41534153This command can be useful to check if a CA file was properly updated.
41544154You can also display the details of an ongoing transaction by prefixing the
4155- filename by an asterisk.
4155+ filename by a '*'. If the first character of the filename is a '*', it can be
4156+ escaped with '\*'.
41564157</ pre > < div class ="separator ">
41574158< span class ="label label-success "> Example :</ span >
41584159< pre class ="prettyprint ">
@@ -4184,13 +4185,14 @@ <h2 id="chapter-9.3" data-target="9.3"><small><a class="small" href="#9.3">9.3.<
41844185Serial: 587A1CE5ED855040A0C82BF255FF300ADB7C8136
41854186[...]
41864187</ code > </ pre >
4187- </ div > < a class ="anchor " name ="show "> </ a > < a class ="anchor " name ="9-show "> </ a > < a class ="anchor " name ="9.3-show "> </ a > < a class ="anchor " name ="show (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl "> </ a > < a class ="anchor " name ="9-show ssl "> </ a > < a class ="anchor " name ="9.3-show ssl "> </ a > < a class ="anchor " name ="show ssl (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl cert "> </ a > < a class ="anchor " name ="9-show ssl cert "> </ a > < a class ="anchor " name ="9.3-show ssl cert "> </ a > < a class ="anchor " name ="show ssl cert (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl cert (Unix Socket commands) "> </ a > < div class ="keyword "> < b > < a class ="anchor " name ="show ssl cert "> </ a > < a href ="#9.3-show%20ssl%20cert "> show ssl cert</ a > </ b > < span style ="color: #008 "> [< span style ="color: #080 "> <filename></ span > ]</ span > </ div > < pre class ="text "> Display the list of certificates loaded into the process. They are not used
4188+ </ div > < a class ="anchor " name ="show "> </ a > < a class ="anchor " name ="9-show "> </ a > < a class ="anchor " name ="9.3-show "> </ a > < a class ="anchor " name ="show (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl "> </ a > < a class ="anchor " name ="9-show ssl "> </ a > < a class ="anchor " name ="9.3-show ssl "> </ a > < a class ="anchor " name ="show ssl (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl cert "> </ a > < a class ="anchor " name ="9-show ssl cert "> </ a > < a class ="anchor " name ="9.3-show ssl cert "> </ a > < a class ="anchor " name ="show ssl cert (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl cert (Unix Socket commands) "> </ a > < div class ="keyword "> < b > < a class ="anchor " name ="show ssl cert "> </ a > < a href ="#9.3-show%20ssl%20cert "> show ssl cert</ a > </ b > < span style ="color: #008 "> [< span style ="color: #008 "> [*]</ span > < span style ="color: #008 "> [\]</ span > < span style ="color: #080 "> <filename></ span > ]</ span > </ div > < pre class ="text "> Display the list of certificates loaded into the process. They are not used
41884189by any frontend or backend until their status is "Used".
41894190If a filename is prefixed by an asterisk, it is a transaction which is not
41904191committed yet. If a filename is specified, it will show details about the
41914192certificate. This command can be useful to check if a certificate was well
41924193updated. You can also display details on a transaction by prefixing the
4193- filename by an asterisk.
4194+ filename by a '*'. If the first character of the filename is a '*', it can be
4195+ escaped with '\*'.
41944196This command can also be used to display the details of a certificate's OCSP
41954197response by suffixing the filename with a ".ocsp" extension. It works for
41964198committed certificates as well as for ongoing transactions. On a committed
@@ -4221,8 +4223,13 @@ <h2 id="chapter-9.3" data-target="9.3"><small><a class="small" href="#9.3">9.3.<
42214223Filename: *test.local.pem
42224224Status: Unused
42234225[...]
4226+
4227+ $ echo "@1 show ssl cert \*.local.pem" | socat /var/run/haproxy.master -
4228+ Filename: *.local.pem
4229+ Status: Used
4230+ [...]
42244231</ code > </ pre >
4225- </ div > < a class ="anchor " name ="show "> </ a > < a class ="anchor " name ="9-show "> </ a > < a class ="anchor " name ="9.3-show "> </ a > < a class ="anchor " name ="show (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl "> </ a > < a class ="anchor " name ="9-show ssl "> </ a > < a class ="anchor " name ="9.3-show ssl "> </ a > < a class ="anchor " name ="show ssl (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl crl-file "> </ a > < a class ="anchor " name ="9-show ssl crl-file "> </ a > < a class ="anchor " name ="9.3-show ssl crl-file "> </ a > < a class ="anchor " name ="show ssl crl-file (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl crl-file (Unix Socket commands) "> </ a > < div class ="keyword "> < b > < a class ="anchor " name ="show ssl crl-file "> </ a > < a href ="#9.3-show%20ssl%20crl-file "> show ssl crl-file</ a > </ b > < span style ="color: #008 "> [< span style ="color: #080 "> <crlfile></ span > < span style ="color: #008 "> [:< span style ="color: #080 "> <index></ span > ]</ span > ]</ span > </ div > < pre class ="text "> Display the list of CRL files loaded into the process. They are not used
4232+ </ div > < a class ="anchor " name ="show "> </ a > < a class ="anchor " name ="9-show "> </ a > < a class ="anchor " name ="9.3-show "> </ a > < a class ="anchor " name ="show (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl "> </ a > < a class ="anchor " name ="9-show ssl "> </ a > < a class ="anchor " name ="9.3-show ssl "> </ a > < a class ="anchor " name ="show ssl (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl crl-file "> </ a > < a class ="anchor " name ="9-show ssl crl-file "> </ a > < a class ="anchor " name ="9.3-show ssl crl-file "> </ a > < a class ="anchor " name ="show ssl crl-file (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl crl-file (Unix Socket commands) "> </ a > < div class ="keyword "> < b > < a class ="anchor " name ="show ssl crl-file "> </ a > < a href ="#9.3-show%20ssl%20crl-file "> show ssl crl-file</ a > </ b > < span style ="color: #008 "> [< span style ="color: #008 "> [*]</ span > < span style ="color: #008 "> [\]</ span > < span style ="color: #080 "> <crlfile></ span > < span style ="color: #008 "> [:< span style ="color: #080 "> <index></ span > ]</ span > ]</ span > </ div > < pre class ="text "> Display the list of CRL files loaded into the process. They are not used
42264233by any frontend or backend until their status is "Used".
42274234If a filename is prefixed by an asterisk, it is a transaction which is not
42284235committed yet. If a <crlfile> is specified without <index>, it will show the
@@ -4234,7 +4241,8 @@ <h2 id="chapter-9.3" data-target="9.3"><small><a class="small" href="#9.3">9.3.<
42344241If the index is invalid (too big for instance), nothing will be displayed.
42354242This command can be useful to check if a CRL file was properly updated.
42364243You can also display the details of an ongoing transaction by prefixing the
4237- filename by an asterisk.
4244+ filename by a '*'. If the first character of the filename is a '*', it can be
4245+ escaped with '\*'.
42384246</ pre > < div class ="separator ">
42394247< span class ="label label-success "> Example :</ span >
42404248< pre class ="prettyprint ">
@@ -4370,11 +4378,14 @@ <h2 id="chapter-9.3" data-target="9.3"><small><a class="small" href="#9.3">9.3.<
43704378 - fips
43714379 - base
43724380</ code > </ pre >
4373- </ div > < a class ="anchor " name ="show "> </ a > < a class ="anchor " name ="9-show "> </ a > < a class ="anchor " name ="9.3-show "> </ a > < a class ="anchor " name ="show (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl "> </ a > < a class ="anchor " name ="9-show ssl "> </ a > < a class ="anchor " name ="9.3-show ssl "> </ a > < a class ="anchor " name ="show ssl (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl sni "> </ a > < a class ="anchor " name ="9-show ssl sni "> </ a > < a class ="anchor " name ="9.3-show ssl sni "> </ a > < a class ="anchor " name ="show ssl sni (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl sni (Unix Socket commands) "> </ a > < div class ="keyword "> < b > < a class ="anchor " name ="show ssl sni "> </ a > < a href ="#9.3-show%20ssl%20sni "> show ssl sni</ a > </ b > < span style ="color: #008 "> [-f < span style ="color: #080 "> <frontend></ span > ]</ span > </ div > < pre class ="text "> Dump every SNI configured for the designated frontend, or all frontends if no
4381+ </ div > < a class ="anchor " name ="show "> </ a > < a class ="anchor " name ="9-show "> </ a > < a class ="anchor " name ="9.3-show "> </ a > < a class ="anchor " name ="show (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl "> </ a > < a class ="anchor " name ="9-show ssl "> </ a > < a class ="anchor " name ="9.3-show ssl "> </ a > < a class ="anchor " name ="show ssl (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl (Unix Socket commands) "> </ a > < a class ="anchor " name ="show ssl sni "> </ a > < a class ="anchor " name ="9-show ssl sni "> </ a > < a class ="anchor " name ="9.3-show ssl sni "> </ a > < a class ="anchor " name ="show ssl sni (Statistics and monitoring) "> </ a > < a class ="anchor " name ="show ssl sni (Unix Socket commands) "> </ a > < div class ="keyword "> < b > < a class ="anchor " name ="show ssl sni "> </ a > < a href ="#9.3-show%20ssl%20sni "> show ssl sni</ a > </ b > < span style ="color: #008 "> [-f < span style ="color: #080 "> <frontend></ span > ]</ span > < span style ="color: #008 "> [-A]</ span > </ div > < pre class ="text "> Dump every SNI configured for the designated frontend, or all frontends if no
43744382frontend was specified. It allows to see what SNI are offered for a frontend,
43754383and to identify if a SNI is defined multiple times by multiple certificates for
43764384the same frontend.
43774385
4386+ The -A option allows to filter the list and only displays the certificates
4387+ that are past the notAfter date, allowing to show only expired certificates.
4388+
43784389Columns are separated by a single \t, allowing to parse it simply.
43794390
43804391The 'Frontend/Bind' column shows the frontend name followed by the bind line
@@ -5435,7 +5446,7 @@ <h2 id="chapter-13.1" data-target="13.1"><small><a class="small" href="#13.1">13
54355446 < br >
54365447 < hr >
54375448 < div class ="text-right ">
5438- HAProxy 3.2-dev1-22 – Management Guide< br >
5449+ HAProxy 3.2-dev1-32 – Management Guide< br >
54395450 < small > , </ small >
54405451 </ div >
54415452 </ div >
0 commit comments