Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But more importantly, you should investigate how your LB or webserver talks to the web app. In many cases that part won't be TLS encrypted and therefore on an HTTP/1.1 channel.

Or even HTTP 1.0 . I found out recently while inspecting some requests in the upstream server that nginx was using HTTP 1.0 after terminating TLS. I was dumbfounded that this was still the default.

http://nginx.org/en/docs/http/ngx_http_proxy_module.html#pro...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: