D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Is HTTPS different?



Mark Evans wrote:
> 
> It certainly is possible to do this, otherwise
> https://www.st-peters-high.devon.sch.uk wouldn't work :)

I figured it should work, as we were using plugdaemon to do this before,
and it doesn't seem to do anything clever.

> Is it making any kind of connection at all?

tcpdump shows the original Syn packet is forwarded to the remote box,
then the intermediate box returns us an ICMP port unreachable - leading
the client to show us a "remote host closed connection", even though I
don't see anything heading back from the remote server, although it is
fun using tcpdump on busy live servers.

BTW: the reason we were trying to switch is that since the Apache
upgrade we are getting a weird interaction between Apache and
plugdaemon. Here some https sessions hang at 8Kbytes downloaded exactly.
If you point browsers straight at the Apache it works.

The weird bit is it is some sessions - on my laptop Konqueror works but
wget fails (100% reproducable). We have the same version of wget
succeeding on some clients, but failing on others (100% reproducible).
Mozilla works, I.E. fails on another client. Doesn't seem to be related
to Agent string (thank Konqueror plugins for te ease of switching). One
of the most difficult to pin down bugs I've ever encountered.

Upgrading plugdaemon solved a long standing problem with plugdaemon not
killing of it's children properly, but didn't alter the 8K problem one iota.

Attachment: pgp00008.pgp
Description: PGP signature


Lynx friendly