Re: Extensions when negotiating TLS

Christopher Schultz <[email protected]> Mon, 4 Nov 2019 17:50:55 -0500
Newsgroups gmane.network.stunnel.user
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============1134364007465990008==
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="51R9Gj5PEFbzcUVVqu84hGrFkYr0d9uzh"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--51R9Gj5PEFbzcUVVqu84hGrFkYr0d9uzh
Content-Type: multipart/mixed; boundary="GHvBDMPbdZwIANBhmYJxN0HkGRtfgtIaH";
 protected-headers="v1"
From: Christopher Schultz <[email protected]>
To: [email protected]
Message-ID: <[email protected]>
Subject: Re: [stunnel-users] Extensions when negotiating TLS
References: <c92c5a6e51824325b83c1bc0f2098847@SN1F00803MB0045.008f.mgd2.msft.net>
 <[email protected]>
 <76d9d4dcfaa74e36acccc9f64be68343@SN1F00803MB0045.008f.mgd2.msft.net>
In-Reply-To: <76d9d4dcfaa74e36acccc9f64be68343@SN1F00803MB0045.008f.mgd2.msft.net>

--GHvBDMPbdZwIANBhmYJxN0HkGRtfgtIaH
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

Tom,

On 11/4/19 17:16, Tom (AST) Watson wrote:
> Yes, I understand about ALPN.  Sorry I described in detail.=20
> Unfortunately application #2 wants encrypted http2 (it is a go
> program). Application #1 wants to talk in http2 (I can't change
> that!) and it doesn't encrypt "naturally" (and I want to see what is
> going on [Wireshark] as well) In looking further I might be able to
> get application #2 to go plaintext (I found a pointer). Yes, it seems
> that stunnel doesn't support ALPN, wishful thinking on my part
>=20
> Back to the salt mines. (*SIGH*)

How difficult would it be to enable HTTP/1.1 on that application #1?
I've never seen an h2-only service before. h2 is more effective for web
applications that make a lot of tiny requests (like small resources for
pages, scripts, etc.). Most API-based services don't really get any
benefit from using h2.

-chris

> -----Original Message----- From: stunnel-users
> <[email protected]> On Behalf Of Christopher Schultz=20
> Sent: Monday, November 4, 2019 13:59 To: [email protected]=20
> Subject: [External] Re: [stunnel-users] Extensions when negotiating
> TLS
>=20
> Tom,
>=20
> On 11/4/19 16:05, Tom (AST) Watson wrote:
>> Well, I thought it would be "easy", but maybe not.  I have an=20
>> application (#1) that uses http2, and isn't encrypted.  No problem
>>  here.  Now I have another application (#2) that insists on using
>> https to talk to application #1.  So I gleefully setup stunnel to
>> connect the two.  Well, application #2 starts talking to stunnel
>> with a "Client Hello" packet, and it includes an extension
>> "Application Layer Protocol Extension" of "h2".
>=20
> This is called ALPN, and is a requirement for h2s.
>=20
>> While not versed in the minutia, I take this that the client=20
>> (application #2) wants to talk "http2" to the server (application
>> #1).
>=20
> Yep, pretty much.
>=20
>> OK, that is what I want.  The problem is that stunnel doesn't
>> respond with ANY "Application Layer Protocol Extension" indicating
>> acceptance of this request in its "server hello".  This means that
>> application #2 fails in its negotiation.  No joy!
>>=20
>> Now I know that application #1 will nicely talk http2, but how do I
>>  get stunnel to communicate this to application #2 (as encrypted=20
>> http2).  Am I missing something in my (pretty simple) configuration
>>  file?
>=20
> I can't find any references to stunnel supporting ALPN. You may be
> (temporarily) out of luck, at least with stunnel.
>=20
> You mentioned that app #2 insists on encryption (great, usually). Is
> there a requirement that it use h2? Or can it be configured to use
> HTTP/1.1?
>=20
> -chris
>=20


--GHvBDMPbdZwIANBhmYJxN0HkGRtfgtIaH--

--51R9Gj5PEFbzcUVVqu84hGrFkYr0d9uzh
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/

iQIzBAEBCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAl3Aq1AACgkQHPApP6U8
pFiBfQ//XOfvWzXmvWm2tLu6J0/33p3J5r9MkRYvvgeupkPA5FOgvuztQMtZz652
zx7KbN1ayU796ZQ0em0bTtzMVQZV9zZ/Xbw+ilhjCL1ZbW4LGGMIHfjftutifRcb
82gXVPD48l4M9su0T/TwXuPbVVwngkZiQBtm2S+e6Du6L+KFzDmFeToQskCcIk+H
5u8J5wXbkbG6mu/oyELM9LAzo/CgifBW5BvtzEjlmRuK7BkIJse3ibA2dv+2ZgBq
gs6aO4yZjd9An6czUSYAZ9SvsfdqqGWIimDyrvDLYaP+F/YJEnof/QOVhl5xH4rV
xKQFkVer7QdV3HMRgovGOBmY5dLslmaMsqffGMEDCwunitPUodAIP2D5WqMMU7TS
D8dSmTn7zIH9dUrtnxj185CZ53nw7PZbsUp5dVs5IQk1qdaXgf0pqbLJDnSA8dGU
IfjKc7S0r+NpqNM6BXyJGPYOz4yH8MPNyjxoo3n2d2ewVSaDsStz0EEl86WMRbMY
egL1TgdbrennG9LcQ19raz0aGsAAQ9BnKM9XQLzGslrEP8ma3dOgg+nXNsftOXe7
7y+1daE6fBOtOYvCoPdyRfwCG7T29js3gfCiIyH2bGtPqt6cTvvsHQUmw/azUH6d
EzJcna3lMn7lEHlRfuYbimDbRF1UxOoYdywuwM28JQzCx8/eCs8=
=E55u
-----END PGP SIGNATURE-----

--51R9Gj5PEFbzcUVVqu84hGrFkYr0d9uzh--

--===============1134364007465990008==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
stunnel-users mailing list
[email protected]
https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users

--===============1134364007465990008==--