]> git.ipfire.org Git - thirdparty/haproxy.git/commitdiff
DOC: examples: provide simplified ssl configuration
authorLukas Tribus <luky-37@hotmail.com>
Thu, 6 Jun 2013 19:26:24 +0000 (21:26 +0200)
committerWilly Tarreau <w@1wt.eu>
Mon, 10 Jun 2013 12:42:05 +0000 (14:42 +0200)
Provides a minimalistic ssl configuration example - no details because
they belong to doc/*.

examples/ssl.cfg [new file with mode: 0644]

diff --git a/examples/ssl.cfg b/examples/ssl.cfg
new file mode 100644 (file)
index 0000000..90ed999
--- /dev/null
@@ -0,0 +1,26 @@
+# This configuration is a simplified example of how to use ssl on front
+# and backends with additional certificates loaded from a directory for SNI
+# capable clients.
+
+global
+       maxconn 100
+
+defaults
+       mode http
+       timeout connect 5s
+       timeout client 5s
+       timeout server 5s
+
+frontend myfrontend
+       # primary cert is /etc/cert/server.pem
+       # /etc/cert/certdir/ contains additional certificates for SNI clients
+       bind :443 ssl crt /etc/cert/server.pem crt /etc/cert/certdir/
+       bind :80
+       default_backend mybackend
+
+backend mybackend
+       # a http backend
+       server s3 10.0.0.3:80
+       # a https backend
+       server s4 10.0.0.3:443 ssl
+