Skip to Content.
Sympa Menu

discuss - [opennic-discuss] [UPDATE] Nearest Server Drama

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

[opennic-discuss] [UPDATE] Nearest Server Drama


Chronological Thread 
  • From: Julian De Marchi <julian AT jdcomputers.com.au>
  • To: discuss AT lists.opennicproject.org
  • Subject: [opennic-discuss] [UPDATE] Nearest Server Drama
  • Date: Tue, 09 Jun 2015 14:48:36 +1000

heya--

Ever since migrating to the new servers the nearest server plugin on the
main site has not worked. After some heavy investigations we found the
root cause to be the load-balancer in use. With the donated funds we
purchased a linode nodebalancer.

The current issue is with the way this nodebalancer does SSL. The
balancer can do the SSL termination itself, but it doesn't support SNI.
Which means we choose only one site to SSL behind the LB and terminate
the rest at the real host. So currently we're just passing TCP through,
which means the REAL_IP gets dropped and replaced with that of the LB.
Using HTTPS in the balancer means the header gets through.

The complications enter. We need to at a minimum SSL LB the wiki and the
main site.

This is it for now on the progress. We're currently discussing methods
to get around this. Just thought it'd be good to get an update "out there".

--julian



Archive powered by MHonArc 2.6.19.

Top of Page