I am using HAproxy as my on-prem load balancer to my Kubernetes cluster. Here is the cfg file:
global
chroot /var/lib/haproxy
pidfile /var/run/haproxy.pid
maxconn 40000
user haproxy
group haproxy
daemon
tune.ssl.default-dh-param 2048
log stdout local0 info
defaults
mode tcp
log global
option httplog
retries 3
timeout http-request 50s
timeout queue 1m
timeout connect 1m
timeout client 1m
timeout server 1m
timeout http-keep-alive 50s
timeout check 10s
maxconn 1000
frontend https_front
mode http
bind *:443 ssl crt /etc/haproxy/haproxy.pem ca-file /etc/haproxy/haproxy.crt verify optional
redirect scheme https if !{ ssl_fc }
acl sadmin path_beg /sadmin
use_backend sadmin_server if sadmin
default_backend sadmin_server
backend sadmin_server
balance roundrobin
mode http
server node1 staging-node1:30000 check
server node2 staging-node2:30000 check
server node3 staging-node3:30000 check
server node4 staging-node4:30000 check
I am using a self signed certificate which has been generated using the traditional openssl commands.
However, while connecting to the website, even though the pages load fine I keep seeing loads of below error:
<134>Oct 18 20:14:14 haproxy[6]: 10.118.108.170:51249 [18/Oct/2019:20:14:14.172] https_front/1: SSL handshake failure
<134>Oct 18 20:14:14 haproxy[6]: 10.118.108.170:51245 [18/Oct/2019:20:14:14.172] https_front/1: SSL handshake failure
<134>Oct 18 20:14:14 haproxy[6]: 10.118.108.170:51247 [18/Oct/2019:20:14:14.172] https_front/1: SSL handshake failure
<134>Oct 18 20:14:14 haproxy[6]: 10.118.108.170:51246 [18/Oct/2019:20:14:14.172] https_front/1: SSL handshake failure
- I have maxed out the connection parameters.
- I tried to load the certificate in the browser as well.
- Have tried the option verified optional & none.
But can't figure out the reason for these errors ?
PS: I have read the pages Haproxy ssl redirect handshake failure and How to track down "Connection timout during SSL handshake" and "Connection closed during ssl handshake" errors and can't find the solution yet.