Compare commits
4 Commits
4fe312929b
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| 9bf4ffad38 | |||
| e6befea75e | |||
| 3a781a129a | |||
| 2769994edd |
BIN
assets/powered_by_netbsd.png
Normal file
BIN
assets/powered_by_netbsd.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 4.9 KiB |
20
index.html
20
index.html
@@ -4,10 +4,11 @@
|
||||
<title>rawley.xyz</title>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="description" value="Rawley Fowler's personal website, about Perl, Emacs and Software in General.">
|
||||
<meta name="keywords" value="Rawley Fowler rawley.xyz emacs netbsd functional clojure perl software architecture bugs fixing maker">
|
||||
<link rel="stylesheet" href="index.css">
|
||||
</head>
|
||||
<body>
|
||||
<div>
|
||||
<div class="blerb">
|
||||
<p>
|
||||
Hi, I'm Rawley. I'm a full-time Husband, Dad, Emacs evangelist and Perl aficionado.
|
||||
</p>
|
||||
@@ -60,6 +61,7 @@
|
||||
</li>
|
||||
</ul>
|
||||
<h2>Noteworthy Projects</h2>
|
||||
<div class="projects">
|
||||
<ul>
|
||||
<li>
|
||||
<a href="https://github.com/mollusc-labs/slapbird">SlapbirdAPM</a>
|
||||
@@ -71,13 +73,19 @@
|
||||
<a href="https://github.com/rawleyfowler/mojolicious-Plugin-IsBot">Mojolicious::Plugin::IsBot</a>
|
||||
</li>
|
||||
</ul>
|
||||
<br />
|
||||
<div>
|
||||
</div>
|
||||
<div class="cards">
|
||||
<a href="http://www.gnu.org/software/emacs">
|
||||
<img src="/assets/gnu_emacs.png"/>
|
||||
<img src="/assets/gnu_emacs.png" width="88" height="31"/>
|
||||
</a>
|
||||
<a href="https://openbsd.org">
|
||||
<img src="/assets/openbsd.gif" style="width: 120px; height 80px" />
|
||||
<a href="http://www.gnu.org/software/emacs">
|
||||
<img src="/assets/made_with_emacs.png" width="88" height="31"/>
|
||||
</a>
|
||||
<a href="https://netbsd.org">
|
||||
<img src="/assets/powered_by_netbsd.png" width="88" height="31"/>
|
||||
</a>
|
||||
<a href="#">
|
||||
<img src="/assets/no_bad_hair_days.png" width="88" height="31"/>
|
||||
</a>
|
||||
</div>
|
||||
<h2>Disclaimer</h2>
|
||||
|
||||
32
posts/fix-apache-sni-behind-alb.html
Normal file
32
posts/fix-apache-sni-behind-alb.html
Normal file
@@ -0,0 +1,32 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Fix Apache 421 SNI Errors Behind AWS ALB</title>
|
||||
<meta content="Description of post" name="description">
|
||||
<meta name="robots">
|
||||
<meta content="keywords" name="Apache SNI Fix 421">
|
||||
<meta content="description" name="How to fix the Apache SNI issues (421 misdirected) behind AWS ALB">
|
||||
<meta charset="utf-8" content="utf-8" name="charset">
|
||||
<link href="/index.css" rel="stylesheet">
|
||||
</head>
|
||||
<body>
|
||||
<a href="/"><< back</a>
|
||||
<h1>Fixing Apache SNI 421 Errors Behind AWS ALB</h1>
|
||||
<h2>Understanding the Problem</h2>
|
||||
<p>
|
||||
SNI (Server Name Indicator) is a flag set in the "Client Hello" of a TLS request. It tells the server what domain you want,
|
||||
without having to decrypt the request later to get the <code>Host</code> header, or whatever else you might be using to route traffic with.
|
||||
Apache uses SNI to figure out what cert to use to decrypt the request. When SNI is missing, or Apache can't find a VHost associated
|
||||
with the domain in the SNI, it will route to the default VHost for decryption and request handling. This is now the default behaviour in 2.4.64 and up,
|
||||
it was applied to fix CVE-2025-23048. Note this is a good change, and means that Apache will reject potentially dangerous requests where SNI isn't the same as the Host header.
|
||||
</p>
|
||||
<h2>Solution</h2>
|
||||
<p>
|
||||
If you're using HTTPS on your Apache, behind an AWS ALB, you're going to run into this issue, because AWS ALB's seemingly don't set SNI at all.
|
||||
The solution is to tell Apache to relax its policy, and allow the default VHost to decrypt the message,
|
||||
and then route on the Host header to the next VHost (I think this is how it works, I could be wrong).
|
||||
You can do this with the <code>SSLVHostSNIPolicy</code> directive, setting it to <code>authonly</code> will
|
||||
return the pre 2.4.64 functionality, however it supposedly only works on 2.4.65, so you may have to skip 2.4.64.
|
||||
</p>
|
||||
</body>
|
||||
</html>
|
||||
Reference in New Issue
Block a user