|
2 | 2 | <html lang="en"> |
3 | 3 | <head> |
4 | 4 | <meta charset="utf-8" /> |
5 | | - <title>HAProxy version 3.2-dev17 - Configuration Manual</title> |
| 5 | + <title>HAProxy version 3.2-dev17-8 - Configuration Manual</title> |
6 | 6 | <link href="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/css/bootstrap.min.css" rel="stylesheet" /> |
7 | 7 | <link href="https://raw.githubusercontent.com/thomaspark/bootswatch/v3.3.7/cerulean/bootstrap.min.css" rel="stylesheet" /> |
8 | 8 | <link href="../css/page.css?0.4.2-15" rel="stylesheet" /> |
|
2611 | 2611 |
|
2612 | 2612 | <a class="list-group-item" href="#no-sslv3">no-sslv3</a> |
2613 | 2613 |
|
| 2614 | + <a class="list-group-item" href="#no-strict-sni">no-strict-sni</a> |
| 2615 | + |
2614 | 2616 | <a class="list-group-item" href="#no-tfo">no-tfo</a> |
2615 | 2617 |
|
2616 | 2618 | <a class="list-group-item" href="#no-tls-tickets (Bind options)">no-tls-tickets (Bind options)</a> |
|
4197 | 4199 |
|
4198 | 4200 | <a class="list-group-item" href="#tls-ticket-keys">tls-ticket-keys</a> |
4199 | 4201 |
|
4200 | | - <a class="list-group-item" href="#tls-tickets">tls-tickets</a> |
| 4202 | + <a class="list-group-item" href="#tls-tickets (Bind options)">tls-tickets (Bind options)</a> |
| 4203 | + |
| 4204 | + <a class="list-group-item" href="#tls-tickets (Server and default-server options)">tls-tickets (Server and default-server options)</a> |
4201 | 4205 |
|
4202 | 4206 | <a class="list-group-item" href="#total-max-size">total-max-size</a> |
4203 | 4207 |
|
|
4606 | 4610 | You can use <strong>left</strong> and <strong>right</strong> arrow keys to navigate between chapters.<br> |
4607 | 4611 | </p> |
4608 | 4612 | <p class="text-right"> |
4609 | | - <small>Converted with <a href="https://github.com/cbonte/haproxy-dconv">haproxy-dconv</a> v<b>0.4.2-15</b> on <b>2025/05/21</b></small> |
| 4613 | + <small>Converted with <a href="https://github.com/cbonte/haproxy-dconv">haproxy-dconv</a> v<b>0.4.2-15</b> on <b>2025/05/22</b></small> |
4610 | 4614 | </p> |
4611 | 4615 | </div> |
4612 | 4616 | <!-- /.sidebar --> |
|
4617 | 4621 | <div class="text-center"> |
4618 | 4622 | <h1><a href="http://www.haproxy.org/" title="HAProxy"><img src="../img/HAProxyCommunityEdition_60px.png?0.4.2-15" /></a></h1> |
4619 | 4623 | <h2>Configuration Manual</h2> |
4620 | | - <p><strong>version 3.2-dev17</strong></p> |
| 4624 | + <p><strong>version 3.2-dev17-8</strong></p> |
4621 | 4625 | <p> |
4622 | 4626 | 2025/05/21<br> |
4623 | 4627 |
|
@@ -21168,6 +21172,11 @@ <h2 id="chapter-5.1" data-target="5.1"><small><a class="small" href="#5.1">5.1.< |
21168 | 21172 | be enabled using any configuration option. This option is also available on |
21169 | 21173 | global statement "<a href="#ssl-default-bind-options">ssl-default-bind-options</a>". Use "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">ssl-min-ver<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#ssl-min-ver%20%28Bind%20options%29">Bind options</a></li><li><a href="#ssl-min-ver%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>" and |
21170 | 21174 | "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">ssl-max-ver<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#ssl-max-ver%20%28Bind%20options%29">Bind options</a></li><li><a href="#ssl-max-ver%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>" instead. |
| 21175 | +</pre><a class="anchor" name="no-strict-sni"></a><a class="anchor" name="5-no-strict-sni"></a><a class="anchor" name="5.1-no-strict-sni"></a><a class="anchor" name="no-strict-sni (Bind and server options)"></a><a class="anchor" name="no-strict-sni (Bind options)"></a><div class="keyword"><b><a class="anchor" name="no-strict-sni"></a><a href="#5.1-no-strict-sni">no-strict-sni</a></b></div><pre class="text">This setting is only available when support for OpenSSL was built in. It |
| 21176 | +disables strict-sni enforcement from a previous "<a href="#strict-sni">strict-sni</a>" directive. It |
| 21177 | +may be needed in order to selectively disable strict-sni usage on a "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">bind<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#bind%20%28Peers%20declaration%29">Peers declaration</a></li><li><a href="#bind%20%28Log%20forwarding%29">Log forwarding</a></li><li><a href="#bind%20%28Alphabetically%20sorted%20keywords%20reference%29">Alphabetically sorted keywords reference</a></li></ul></span>" |
| 21178 | +line when it was already globally enforced via "<a href="#ssl-default-bind-options">ssl-default-bind-options</a>". |
| 21179 | +See also the "<a href="#strict-sni">strict-sni</a>" bind option. |
21171 | 21180 | </pre><a class="anchor" name="no-tls-tickets"></a><a class="anchor" name="5-no-tls-tickets"></a><a class="anchor" name="5.1-no-tls-tickets"></a><a class="anchor" name="no-tls-tickets (Bind and server options)"></a><a class="anchor" name="no-tls-tickets (Bind options)"></a><div class="keyword"><b><a class="anchor" name="no-tls-tickets"></a><a href="#5.1-no-tls-tickets">no-tls-tickets</a></b></div><pre class="text">This setting is only available when support for OpenSSL was built in. It |
21172 | 21181 | disables the stateless session resumption (RFC 5077 TLS Ticket |
21173 | 21182 | extension) and force to use stateful session resumption. Stateless |
@@ -21347,9 +21356,10 @@ <h2 id="chapter-5.1" data-target="5.1"><small><a class="small" href="#5.1">5.1.< |
21347 | 21356 | SSL/TLS negotiation is allowed only if the client provided an SNI that matches |
21348 | 21357 | a certificate. The default certificate is not used. This option also allows |
21349 | 21358 | starting without any certificate on a bind line, so an empty directory could |
21350 | | -be used and filled later from the stats socket. |
21351 | | -See the "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">crt<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#crt%20%28Load%20options%29">Load options</a></li><li><a href="#crt%20%28Bind%20options%29">Bind options</a></li><li><a href="#crt%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>" option for more information. See "add ssl crt-list" command in |
21352 | | -the management guide. |
| 21359 | +be used and filled later from the stats socket. This option is also available |
| 21360 | +on global statement "<a href="#ssl-default-bind-options">ssl-default-bind-options</a>", and may be selectively |
| 21361 | +disabled on a "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">bind<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#bind%20%28Peers%20declaration%29">Peers declaration</a></li><li><a href="#bind%20%28Log%20forwarding%29">Log forwarding</a></li><li><a href="#bind%20%28Alphabetically%20sorted%20keywords%20reference%29">Alphabetically sorted keywords reference</a></li></ul></span>" line using "<a href="#no-strict-sni">no-strict-sni</a>". See the "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">crt<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#crt%20%28Load%20options%29">Load options</a></li><li><a href="#crt%20%28Bind%20options%29">Bind options</a></li><li><a href="#crt%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>" option for |
| 21362 | +more information. See "add ssl crt-list" command in the management guide. |
21353 | 21363 | </pre><a class="anchor" name="tcp-ut"></a><a class="anchor" name="5-tcp-ut"></a><a class="anchor" name="5.1-tcp-ut"></a><a class="anchor" name="tcp-ut (Bind and server options)"></a><a class="anchor" name="tcp-ut (Bind options)"></a><div class="keyword"><b><a class="anchor" name="tcp-ut"></a><a href="#5.1-tcp-ut">tcp-ut</a></b> <span style="color: #080"><delay></span></div><pre class="text">Sets the TCP User Timeout for all incoming connections instantiated from this |
21354 | 21364 | listening socket. This option is available on Linux since version 2.6.37. It |
21355 | 21365 | allows HAProxy to configure a timeout for sockets which contain data not |
@@ -21431,6 +21441,11 @@ <h2 id="chapter-5.1" data-target="5.1"><small><a class="small" href="#5.1">5.1.< |
21431 | 21441 | This keyword is compatible with reverse HTTP binds. However, it is forbidden |
21432 | 21442 | to specify a thread set which spans across several thread groups for such a |
21433 | 21443 | listener as this may caused "<a href="#nbconn">nbconn</a>" to not work as intended. |
| 21444 | +</pre><a class="anchor" name="tls-tickets"></a><a class="anchor" name="5-tls-tickets"></a><a class="anchor" name="5.1-tls-tickets"></a><a class="anchor" name="tls-tickets (Bind and server options)"></a><a class="anchor" name="tls-tickets (Bind options)"></a><div class="keyword"><b><a class="anchor" name="tls-tickets"></a><a href="#5.1-tls-tickets">tls-tickets</a></b></div><pre class="text">This setting is only available when support for OpenSSL was built in. It |
| 21445 | +enables the stateless session resumption (RFC 5077 TLS Ticket extension). It |
| 21446 | +is the default, but it may be needed to selectively re-enable the feature on |
| 21447 | +a "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">bind<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#bind%20%28Peers%20declaration%29">Peers declaration</a></li><li><a href="#bind%20%28Log%20forwarding%29">Log forwarding</a></li><li><a href="#bind%20%28Alphabetically%20sorted%20keywords%20reference%29">Alphabetically sorted keywords reference</a></li></ul></span>" line if it had been globaly disabled via "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">no-tls-tickets<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#no-tls-tickets%20%28Bind%20options%29">Bind options</a></li><li><a href="#no-tls-tickets%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>" mentioned |
| 21448 | +in "<a href="#ssl-default-bind-options">ssl-default-bind-options</a>". See also the "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">no-tls-tickets<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#no-tls-tickets%20%28Bind%20options%29">Bind options</a></li><li><a href="#no-tls-tickets%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>" bind keyword. |
21434 | 21449 | </pre><a class="anchor" name="tls-ticket-keys"></a><a class="anchor" name="5-tls-ticket-keys"></a><a class="anchor" name="5.1-tls-ticket-keys"></a><a class="anchor" name="tls-ticket-keys (Bind and server options)"></a><a class="anchor" name="tls-ticket-keys (Bind options)"></a><div class="keyword"><b><a class="anchor" name="tls-ticket-keys"></a><a href="#5.1-tls-ticket-keys">tls-ticket-keys</a></b> <span style="color: #080"><keyfile></span></div><pre class="text">Sets the TLS ticket keys file to load the keys from. The keys need to be 48 |
21435 | 21450 | or 80 bytes long, depending if aes128 or aes256 is used, encoded with base64 |
21436 | 21451 | with one line per key (ex. openssl rand 80 | openssl base64 -A | xargs echo). |
@@ -22252,7 +22267,7 @@ <h2 id="chapter-5.2" data-target="5.2"><small><a class="small" href="#5.2">5.2.< |
22252 | 22267 | The TLS ticket mechanism is only used up to TLS 1.2. |
22253 | 22268 | Forward Secrecy is compromised with TLS tickets, unless ticket keys |
22254 | 22269 | are periodically rotated (via reload or by using "<a href="#tls-ticket-keys">tls-ticket-keys</a>"). |
22255 | | -See also "<a href="#tls-tickets">tls-tickets</a>". |
| 22270 | +See also "<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">tls-tickets<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#tls-tickets%20%28Bind%20options%29">Bind options</a></li><li><a href="#tls-tickets%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>". |
22256 | 22271 | </pre><a class="anchor" name="no-tlsv10"></a><a class="anchor" name="5-no-tlsv10"></a><a class="anchor" name="5.2-no-tlsv10"></a><a class="anchor" name="no-tlsv10 (Bind and server options)"></a><a class="anchor" name="no-tlsv10 (Server and default-server options)"></a><div class="keyword"><b><a class="anchor" name="no-tlsv10"></a><a href="#5.2-no-tlsv10">no-tlsv10</a></b></div><pre class="text">May be used in the following contexts: tcp, http, log, peers, ring |
22257 | 22272 |
|
22258 | 22273 | This option disables support for TLSv1.0 when SSL is used to communicate with |
@@ -32987,7 +33002,7 @@ <h2 id="chapter-12.9" data-target="12.9"><small><a class="small" href="#12.9">12 |
32987 | 33002 | <br> |
32988 | 33003 | <hr> |
32989 | 33004 | <div class="text-right"> |
32990 | | - HAProxy 3.2-dev17 – Configuration Manual<br> |
| 33005 | + HAProxy 3.2-dev17-8 – Configuration Manual<br> |
32991 | 33006 | <small>, 2025/05/21</small> |
32992 | 33007 | </div> |
32993 | 33008 | </div> |
|
0 commit comments