Skip to content

Commit f0e28a6

Browse files
author
HAProxy Community
committed
Update docs for dev
1 parent a14e0b3 commit f0e28a6

File tree

3 files changed

+40
-92
lines changed

3 files changed

+40
-92
lines changed

docs/dev/configuration.html

Lines changed: 24 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
<html lang="en">
33
<head>
44
<meta charset="utf-8" />
5-
<title>HAProxy version 3.2-dev17 - Configuration Manual</title>
5+
<title>HAProxy version 3.2-dev17-8 - Configuration Manual</title>
66
<link href="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/css/bootstrap.min.css" rel="stylesheet" />
77
<link href="https://raw.githubusercontent.com/thomaspark/bootswatch/v3.3.7/cerulean/bootstrap.min.css" rel="stylesheet" />
88
<link href="../css/page.css?0.4.2-15" rel="stylesheet" />
@@ -2611,6 +2611,8 @@
26112611

26122612
<a class="list-group-item" href="#no-sslv3">no-sslv3</a>
26132613

2614+
<a class="list-group-item" href="#no-strict-sni">no-strict-sni</a>
2615+
26142616
<a class="list-group-item" href="#no-tfo">no-tfo</a>
26152617

26162618
<a class="list-group-item" href="#no-tls-tickets (Bind options)">no-tls-tickets (Bind options)</a>
@@ -4197,7 +4199,9 @@
41974199

41984200
<a class="list-group-item" href="#tls-ticket-keys">tls-ticket-keys</a>
41994201

4200-
<a class="list-group-item" href="#tls-tickets">tls-tickets</a>
4202+
<a class="list-group-item" href="#tls-tickets (Bind options)">tls-tickets (Bind options)</a>
4203+
4204+
<a class="list-group-item" href="#tls-tickets (Server and default-server options)">tls-tickets (Server and default-server options)</a>
42014205

42024206
<a class="list-group-item" href="#total-max-size">total-max-size</a>
42034207

@@ -4606,7 +4610,7 @@
46064610
You can use <strong>left</strong> and <strong>right</strong> arrow keys to navigate between chapters.<br>
46074611
</p>
46084612
<p class="text-right">
4609-
<small>Converted with <a href="https://github.com/cbonte/haproxy-dconv">haproxy-dconv</a> v<b>0.4.2-15</b> on <b>2025/05/21</b></small>
4613+
<small>Converted with <a href="https://github.com/cbonte/haproxy-dconv">haproxy-dconv</a> v<b>0.4.2-15</b> on <b>2025/05/22</b></small>
46104614
</p>
46114615
</div>
46124616
<!-- /.sidebar -->
@@ -4617,7 +4621,7 @@
46174621
<div class="text-center">
46184622
<h1><a href="http://www.haproxy.org/" title="HAProxy"><img src="../img/HAProxyCommunityEdition_60px.png?0.4.2-15" /></a></h1>
46194623
<h2>Configuration Manual</h2>
4620-
<p><strong>version 3.2-dev17</strong></p>
4624+
<p><strong>version 3.2-dev17-8</strong></p>
46214625
<p>
46224626
2025/05/21<br>
46234627

@@ -21168,6 +21172,11 @@ <h2 id="chapter-5.1" data-target="5.1"><small><a class="small" href="#5.1">5.1.<
2116821172
be enabled using any configuration option. This option is also available on
2116921173
global statement &quot;<a href="#ssl-default-bind-options">ssl-default-bind-options</a>&quot;. Use &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">ssl-min-ver<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#ssl-min-ver%20%28Bind%20options%29">Bind options</a></li><li><a href="#ssl-min-ver%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>&quot; and
2117021174
&quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">ssl-max-ver<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#ssl-max-ver%20%28Bind%20options%29">Bind options</a></li><li><a href="#ssl-max-ver%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>&quot; instead.
21175+
</pre><a class="anchor" name="no-strict-sni"></a><a class="anchor" name="5-no-strict-sni"></a><a class="anchor" name="5.1-no-strict-sni"></a><a class="anchor" name="no-strict-sni (Bind and server options)"></a><a class="anchor" name="no-strict-sni (Bind options)"></a><div class="keyword"><b><a class="anchor" name="no-strict-sni"></a><a href="#5.1-no-strict-sni">no-strict-sni</a></b></div><pre class="text">This setting is only available when support for OpenSSL was built in. It
21176+
disables strict-sni enforcement from a previous &quot;<a href="#strict-sni">strict-sni</a>&quot; directive. It
21177+
may be needed in order to selectively disable strict-sni usage on a &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">bind<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#bind%20%28Peers%20declaration%29">Peers declaration</a></li><li><a href="#bind%20%28Log%20forwarding%29">Log forwarding</a></li><li><a href="#bind%20%28Alphabetically%20sorted%20keywords%20reference%29">Alphabetically sorted keywords reference</a></li></ul></span>&quot;
21178+
line when it was already globally enforced via &quot;<a href="#ssl-default-bind-options">ssl-default-bind-options</a>&quot;.
21179+
See also the &quot;<a href="#strict-sni">strict-sni</a>&quot; bind option.
2117121180
</pre><a class="anchor" name="no-tls-tickets"></a><a class="anchor" name="5-no-tls-tickets"></a><a class="anchor" name="5.1-no-tls-tickets"></a><a class="anchor" name="no-tls-tickets (Bind and server options)"></a><a class="anchor" name="no-tls-tickets (Bind options)"></a><div class="keyword"><b><a class="anchor" name="no-tls-tickets"></a><a href="#5.1-no-tls-tickets">no-tls-tickets</a></b></div><pre class="text">This setting is only available when support for OpenSSL was built in. It
2117221181
disables the stateless session resumption (RFC 5077 TLS Ticket
2117321182
extension) and force to use stateful session resumption. Stateless
@@ -21347,9 +21356,10 @@ <h2 id="chapter-5.1" data-target="5.1"><small><a class="small" href="#5.1">5.1.<
2134721356
SSL/TLS negotiation is allowed only if the client provided an SNI that matches
2134821357
a certificate. The default certificate is not used. This option also allows
2134921358
starting without any certificate on a bind line, so an empty directory could
21350-
be used and filled later from the stats socket.
21351-
See the &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">crt<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#crt%20%28Load%20options%29">Load options</a></li><li><a href="#crt%20%28Bind%20options%29">Bind options</a></li><li><a href="#crt%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>&quot; option for more information. See &quot;add ssl crt-list&quot; command in
21352-
the management guide.
21359+
be used and filled later from the stats socket. This option is also available
21360+
on global statement &quot;<a href="#ssl-default-bind-options">ssl-default-bind-options</a>&quot;, and may be selectively
21361+
disabled on a &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">bind<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#bind%20%28Peers%20declaration%29">Peers declaration</a></li><li><a href="#bind%20%28Log%20forwarding%29">Log forwarding</a></li><li><a href="#bind%20%28Alphabetically%20sorted%20keywords%20reference%29">Alphabetically sorted keywords reference</a></li></ul></span>&quot; line using &quot;<a href="#no-strict-sni">no-strict-sni</a>&quot;. See the &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">crt<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#crt%20%28Load%20options%29">Load options</a></li><li><a href="#crt%20%28Bind%20options%29">Bind options</a></li><li><a href="#crt%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>&quot; option for
21362+
more information. See &quot;add ssl crt-list&quot; command in the management guide.
2135321363
</pre><a class="anchor" name="tcp-ut"></a><a class="anchor" name="5-tcp-ut"></a><a class="anchor" name="5.1-tcp-ut"></a><a class="anchor" name="tcp-ut (Bind and server options)"></a><a class="anchor" name="tcp-ut (Bind options)"></a><div class="keyword"><b><a class="anchor" name="tcp-ut"></a><a href="#5.1-tcp-ut">tcp-ut</a></b> <span style="color: #080">&lt;delay&gt;</span></div><pre class="text">Sets the TCP User Timeout for all incoming connections instantiated from this
2135421364
listening socket. This option is available on Linux since version 2.6.37. It
2135521365
allows HAProxy to configure a timeout for sockets which contain data not
@@ -21431,6 +21441,11 @@ <h2 id="chapter-5.1" data-target="5.1"><small><a class="small" href="#5.1">5.1.<
2143121441
This keyword is compatible with reverse HTTP binds. However, it is forbidden
2143221442
to specify a thread set which spans across several thread groups for such a
2143321443
listener as this may caused &quot;<a href="#nbconn">nbconn</a>&quot; to not work as intended.
21444+
</pre><a class="anchor" name="tls-tickets"></a><a class="anchor" name="5-tls-tickets"></a><a class="anchor" name="5.1-tls-tickets"></a><a class="anchor" name="tls-tickets (Bind and server options)"></a><a class="anchor" name="tls-tickets (Bind options)"></a><div class="keyword"><b><a class="anchor" name="tls-tickets"></a><a href="#5.1-tls-tickets">tls-tickets</a></b></div><pre class="text">This setting is only available when support for OpenSSL was built in. It
21445+
enables the stateless session resumption (RFC 5077 TLS Ticket extension). It
21446+
is the default, but it may be needed to selectively re-enable the feature on
21447+
a &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">bind<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#bind%20%28Peers%20declaration%29">Peers declaration</a></li><li><a href="#bind%20%28Log%20forwarding%29">Log forwarding</a></li><li><a href="#bind%20%28Alphabetically%20sorted%20keywords%20reference%29">Alphabetically sorted keywords reference</a></li></ul></span>&quot; line if it had been globaly disabled via &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">no-tls-tickets<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#no-tls-tickets%20%28Bind%20options%29">Bind options</a></li><li><a href="#no-tls-tickets%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>&quot; mentioned
21448+
in &quot;<a href="#ssl-default-bind-options">ssl-default-bind-options</a>&quot;. See also the &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">no-tls-tickets<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#no-tls-tickets%20%28Bind%20options%29">Bind options</a></li><li><a href="#no-tls-tickets%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>&quot; bind keyword.
2143421449
</pre><a class="anchor" name="tls-ticket-keys"></a><a class="anchor" name="5-tls-ticket-keys"></a><a class="anchor" name="5.1-tls-ticket-keys"></a><a class="anchor" name="tls-ticket-keys (Bind and server options)"></a><a class="anchor" name="tls-ticket-keys (Bind options)"></a><div class="keyword"><b><a class="anchor" name="tls-ticket-keys"></a><a href="#5.1-tls-ticket-keys">tls-ticket-keys</a></b> <span style="color: #080">&lt;keyfile&gt;</span></div><pre class="text">Sets the TLS ticket keys file to load the keys from. The keys need to be 48
2143521450
or 80 bytes long, depending if aes128 or aes256 is used, encoded with base64
2143621451
with one line per key (ex. openssl rand 80 | openssl base64 -A | xargs echo).
@@ -22252,7 +22267,7 @@ <h2 id="chapter-5.2" data-target="5.2"><small><a class="small" href="#5.2">5.2.<
2225222267
The TLS ticket mechanism is only used up to TLS 1.2.
2225322268
Forward Secrecy is compromised with TLS tickets, unless ticket keys
2225422269
are periodically rotated (via reload or by using &quot;<a href="#tls-ticket-keys">tls-ticket-keys</a>&quot;).
22255-
See also &quot;<a href="#tls-tickets">tls-tickets</a>&quot;.
22270+
See also &quot;<span class="dropdown"><a class="dropdown-toggle" data-toggle="dropdown" href="#">tls-tickets<span class="caret"></span></a><ul class="dropdown-menu"><li class="dropdown-header">This keyword is available in sections :</li><li><a href="#tls-tickets%20%28Bind%20options%29">Bind options</a></li><li><a href="#tls-tickets%20%28Server%20and%20default-server%20options%29">Server and default-server options</a></li></ul></span>&quot;.
2225622271
</pre><a class="anchor" name="no-tlsv10"></a><a class="anchor" name="5-no-tlsv10"></a><a class="anchor" name="5.2-no-tlsv10"></a><a class="anchor" name="no-tlsv10 (Bind and server options)"></a><a class="anchor" name="no-tlsv10 (Server and default-server options)"></a><div class="keyword"><b><a class="anchor" name="no-tlsv10"></a><a href="#5.2-no-tlsv10">no-tlsv10</a></b></div><pre class="text">May be used in the following contexts: tcp, http, log, peers, ring
2225722272

2225822273
This option disables support for TLSv1.0 when SSL is used to communicate with
@@ -32987,7 +33002,7 @@ <h2 id="chapter-12.9" data-target="12.9"><small><a class="small" href="#12.9">12
3298733002
<br>
3298833003
<hr>
3298933004
<div class="text-right">
32990-
HAProxy 3.2-dev17 &ndash; Configuration Manual<br>
33005+
HAProxy 3.2-dev17-8 &ndash; Configuration Manual<br>
3299133006
<small>, 2025/05/21</small>
3299233007
</div>
3299333008
</div>

docs/dev/intro.html

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
<html lang="en">
33
<head>
44
<meta charset="utf-8" />
5-
<title>HAProxy version 3.2-dev17 - Starter Guide</title>
5+
<title>HAProxy version 3.2-dev17-8 - Starter Guide</title>
66
<link href="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/css/bootstrap.min.css" rel="stylesheet" />
77
<link href="https://raw.githubusercontent.com/thomaspark/bootswatch/v3.3.7/cerulean/bootstrap.min.css" rel="stylesheet" />
88
<link href="../css/page.css?0.4.2-15" rel="stylesheet" />
@@ -484,7 +484,7 @@
484484
You can use <strong>left</strong> and <strong>right</strong> arrow keys to navigate between chapters.<br>
485485
</p>
486486
<p class="text-right">
487-
<small>Converted with <a href="https://github.com/cbonte/haproxy-dconv">haproxy-dconv</a> v<b>0.4.2-15</b> on <b>2025/05/21</b></small>
487+
<small>Converted with <a href="https://github.com/cbonte/haproxy-dconv">haproxy-dconv</a> v<b>0.4.2-15</b> on <b>2025/05/22</b></small>
488488
</p>
489489
</div>
490490
<!-- /.sidebar -->
@@ -495,7 +495,7 @@
495495
<div class="text-center">
496496
<h1><a href="http://www.haproxy.org/" title="HAProxy"><img src="../img/HAProxyCommunityEdition_60px.png?0.4.2-15" /></a></h1>
497497
<h2>Starter Guide</h2>
498-
<p><strong>version 3.2-dev17</strong></p>
498+
<p><strong>version 3.2-dev17-8</strong></p>
499499
<p>
500500
<br>
501501

@@ -2515,7 +2515,7 @@ <h2 id="chapter-4.4" data-target="4.4"><small><a class="small" href="#4.4">4.4.<
25152515
<br>
25162516
<hr>
25172517
<div class="text-right">
2518-
HAProxy 3.2-dev17 &ndash; Starter Guide<br>
2518+
HAProxy 3.2-dev17-8 &ndash; Starter Guide<br>
25192519
<small>, </small>
25202520
</div>
25212521
</div>

0 commit comments

Comments
 (0)