Re: Extensions when negotiating TLS
Christopher Schultz <[email protected]> Mon, 4 Nov 2019 17:50:55 -0500
| Newsgroups | gmane.network.stunnel.user |
|---|---|
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============1134364007465990008== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="51R9Gj5PEFbzcUVVqu84hGrFkYr0d9uzh" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --51R9Gj5PEFbzcUVVqu84hGrFkYr0d9uzh Content-Type: multipart/mixed; boundary="GHvBDMPbdZwIANBhmYJxN0HkGRtfgtIaH"; protected-headers="v1" From: Christopher Schultz <[email protected]> To: [email protected] Message-ID: <[email protected]> Subject: Re: [stunnel-users] Extensions when negotiating TLS References: <c92c5a6e51824325b83c1bc0f2098847@SN1F00803MB0045.008f.mgd2.msft.net> <[email protected]> <76d9d4dcfaa74e36acccc9f64be68343@SN1F00803MB0045.008f.mgd2.msft.net> In-Reply-To: <76d9d4dcfaa74e36acccc9f64be68343@SN1F00803MB0045.008f.mgd2.msft.net> --GHvBDMPbdZwIANBhmYJxN0HkGRtfgtIaH Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: quoted-printable Tom, On 11/4/19 17:16, Tom (AST) Watson wrote: > Yes, I understand about ALPN. Sorry I described in detail.=20 > Unfortunately application #2 wants encrypted http2 (it is a go > program). Application #1 wants to talk in http2 (I can't change > that!) and it doesn't encrypt "naturally" (and I want to see what is > going on [Wireshark] as well) In looking further I might be able to > get application #2 to go plaintext (I found a pointer). Yes, it seems > that stunnel doesn't support ALPN, wishful thinking on my part >=20 > Back to the salt mines. (*SIGH*) How difficult would it be to enable HTTP/1.1 on that application #1? I've never seen an h2-only service before. h2 is more effective for web applications that make a lot of tiny requests (like small resources for pages, scripts, etc.). Most API-based services don't really get any benefit from using h2. -chris > -----Original Message----- From: stunnel-users > <[email protected]> On Behalf Of Christopher Schultz=20 > Sent: Monday, November 4, 2019 13:59 To: [email protected]=20 > Subject: [External] Re: [stunnel-users] Extensions when negotiating > TLS >=20 > Tom, >=20 > On 11/4/19 16:05, Tom (AST) Watson wrote: >> Well, I thought it would be "easy", but maybe not. I have an=20 >> application (#1) that uses http2, and isn't encrypted. No problem >> here. Now I have another application (#2) that insists on using >> https to talk to application #1. So I gleefully setup stunnel to >> connect the two. Well, application #2 starts talking to stunnel >> with a "Client Hello" packet, and it includes an extension >> "Application Layer Protocol Extension" of "h2". >=20 > This is called ALPN, and is a requirement for h2s. >=20 >> While not versed in the minutia, I take this that the client=20 >> (application #2) wants to talk "http2" to the server (application >> #1). >=20 > Yep, pretty much. >=20 >> OK, that is what I want. The problem is that stunnel doesn't >> respond with ANY "Application Layer Protocol Extension" indicating >> acceptance of this request in its "server hello". This means that >> application #2 fails in its negotiation. No joy! >>=20 >> Now I know that application #1 will nicely talk http2, but how do I >> get stunnel to communicate this to application #2 (as encrypted=20 >> http2). Am I missing something in my (pretty simple) configuration >> file? >=20 > I can't find any references to stunnel supporting ALPN. You may be > (temporarily) out of luck, at least with stunnel. >=20 > You mentioned that app #2 insists on encryption (great, usually). Is > there a requirement that it use h2? Or can it be configured to use > HTTP/1.1? >=20 > -chris >=20 --GHvBDMPbdZwIANBhmYJxN0HkGRtfgtIaH-- --51R9Gj5PEFbzcUVVqu84hGrFkYr0d9uzh Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/ iQIzBAEBCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAl3Aq1AACgkQHPApP6U8 pFiBfQ//XOfvWzXmvWm2tLu6J0/33p3J5r9MkRYvvgeupkPA5FOgvuztQMtZz652 zx7KbN1ayU796ZQ0em0bTtzMVQZV9zZ/Xbw+ilhjCL1ZbW4LGGMIHfjftutifRcb 82gXVPD48l4M9su0T/TwXuPbVVwngkZiQBtm2S+e6Du6L+KFzDmFeToQskCcIk+H 5u8J5wXbkbG6mu/oyELM9LAzo/CgifBW5BvtzEjlmRuK7BkIJse3ibA2dv+2ZgBq gs6aO4yZjd9An6czUSYAZ9SvsfdqqGWIimDyrvDLYaP+F/YJEnof/QOVhl5xH4rV xKQFkVer7QdV3HMRgovGOBmY5dLslmaMsqffGMEDCwunitPUodAIP2D5WqMMU7TS D8dSmTn7zIH9dUrtnxj185CZ53nw7PZbsUp5dVs5IQk1qdaXgf0pqbLJDnSA8dGU IfjKc7S0r+NpqNM6BXyJGPYOz4yH8MPNyjxoo3n2d2ewVSaDsStz0EEl86WMRbMY egL1TgdbrennG9LcQ19raz0aGsAAQ9BnKM9XQLzGslrEP8ma3dOgg+nXNsftOXe7 7y+1daE6fBOtOYvCoPdyRfwCG7T29js3gfCiIyH2bGtPqt6cTvvsHQUmw/azUH6d EzJcna3lMn7lEHlRfuYbimDbRF1UxOoYdywuwM28JQzCx8/eCs8= =E55u -----END PGP SIGNATURE----- --51R9Gj5PEFbzcUVVqu84hGrFkYr0d9uzh-- --===============1134364007465990008== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ stunnel-users mailing list [email protected] https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users --===============1134364007465990008==--