global uid 80 gid 80 chroot /var/haproxy daemon stats socket /var/run/haproxy.socket group proxy mode 775 level admin nbthread 6 hard-stop-after 60s no strict-limits tune.ssl.ocsp-update.mindelay 300 tune.ssl.ocsp-update.maxdelay 3600 httpclient.resolvers.prefer ipv4 tune.ssl.default-dh-param 2048 spread-checks 2 tune.bufsize 16384 tune.lua.maxmem 0 log /var/run/log local0 info lua-prepend-path /tmp/haproxy/lua/?.luadefaults log global option redispatch -1 timeout client 30s timeout connect 30s timeout server 30s retries 3 default-server init-addr last,libc# autogenerated entries for ACLs# autogenerated entries for config in backends/frontends# autogenerated entries for stats# Frontend: Letsencrypt_80 (Letsencrypt_80)frontend Letsencrypt_80 bind 10.50.52.2:80 name 10.50.52.2:80 mode tcp # logging options# Frontend: LetsEncrypt_443 (LetsEncrypt_443)frontend LetsEncrypt_443 http-response set-header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload" bind 10.50.52.2:443 name 10.50.52.2:443 ssl prefer-client-ciphers ssl-min-ver TLSv1.2 ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256 ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256 alpn h2,http/1.1 crt-list /tmp/haproxy/ssl/665363d00b6901.61101611.certlist mode http option http-keep-alive default_backend acme_challenge_backend option forwardfor # logging options # ACL: find_acme_challenge acl acl_665360c0b7aef6.55967259 path_beg -i /.well-known/acme-challenge/ # ACL: DIM01CHECKMK acl acl_66536313ce2220.70622935 hdr(host) -i checkmk.test.de # ACTION: redirect_acme_challenges use_backend acme_challenge_backend if acl_665360c0b7aef6.55967259 # ACTION: DIM01CHECKMK use_backend DIM01CHMK if acl_66536313ce2220.70622935# Backend: acme_challenge_backend (Added by ACME Client plugin)backend acme_challenge_backend # health checking is DISABLED mode http balance source # stickiness stick-table type ip size 50k expire 30m stick on src http-reuse safe# Backend: DIM01CHMK ()backend DIM01CHMK # health checking is DISABLED mode http balance source # stickiness stick-table type ip size 50k expire 30m stick on src http-reuse safe server DIM01CHMK 10.50.50.4:443 ssl verify required ca-file /etc/ssl/cert.pem# statistics are DISABLED
Ich habe noch 4 weitere Opnsense Server mit HAProxy, da funktioniert alles.