

![]() | Start a set with this search |
![]() | Include this search in one of my sets |
![]() | Exclude this search from one of my sets |
![]() | Permalink to these results Paste this link in email or IM: |
| Atom feed for tracking future search results Paste this URL into your reader: |
10 messages in ru.sysoev.nginxRe: SSL Strangeness| From | Sent On | Attachments |
|---|---|---|
| Curtis Spencer | Nov 28, 2007 6:52 pm | |
| Curtis Spencer | Nov 28, 2007 6:53 pm | |
| Igor Sysoev | Nov 28, 2007 11:04 pm | |
| Curtis Spencer | Nov 29, 2007 1:16 pm | |
| Aleksandar Lazic | Nov 30, 2007 1:32 am | |
| Curtis Spencer | Nov 30, 2007 11:35 am | |
| Curtis Spencer | Dec 10, 2007 3:12 pm | |
| Igor Sysoev | Dec 11, 2007 12:00 am | |
| Curtis Spencer | Dec 11, 2007 12:15 pm | |
| Igor Sysoev | Dec 11, 2007 10:59 pm |

![]() | Permalink for this message Paste this link in email or IM: |
![]() | Permalink for this thread Paste this link in email or IM: |
| Atom feed for this thread Paste this URL into your reader: |
| Subject: | Re: SSL Strangeness | Actions... |
|---|---|---|
| From: | Curtis Spencer (thor...@public.gmane.org) | |
| Date: | Nov 28, 2007 6:53:53 pm | |
| List: | ru.sysoev.nginx | |
forgot to mention that I am running nginx 0.5.33 with the following use flags on Gentoo: USE="pcre perl ssl zlib -debug -fastcgi -flv -imap -status -sub -webdav"
On Nov 28, 2007 6:53 PM, Curtis Spencer
<thor...@public.gmane.org> wrote:
Hi,
I am running 4 mongrels behind nginx with two servers blocks (one ssl enabled). I have a public facing app that 20-30 users go through each day (non ssl) and administrative SSL controllers in the app that people at my office use. I am noticing that by the end of day after a lot of use of the SSL version of the app, that some requests are hanging for certain people in the office (Mac OSX and Windows Firefox 2.0.0.5-10). It very rarely hangs on my machine (Linux), but it happens every now and then. I don't think the mongrels are dying because usually when these people encounter the hangs we can go to other computers (Linux Windows OSX) in the office and hammer on the SSL portion of site with no problems. Also, the non SSL version of the site never has any hanging AFAIK.
My server settings look like this (which is mainly Ezra's Default conf for mongrels):
server { server_name www.mydomain.com; listen 443;
ssl on; ssl_certificate /var/keys/www.mydomain.com.pem; ssl_certificate_key /var/keys/www.mydomain.com.np.pem;
client_max_body_size 50M;
# doc root root /var/www/www.mydomain.com/current/public;
# vhost specific access log access_log /var/log/nginx/ssl.www.mydomain.com.access.log main;
# this rewrites all the requests to the maintenance.html # page if it exists in the doc root. This is for capistrano's # disable web task if (-f $document_root/system/maintenance.html) { rewrite ^(.*)$ /system/maintenance.html last; break; }
location / { # needed to forward user's IP address to rails proxy_set_header X-Real-IP $remote_addr;
# needed for HTTPS proxy_set_header X-FORWARDED_PROTO https; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Host $http_host; proxy_max_temp_file_size 0; proxy_redirect false;# If the file exists as a static file serve it directly without # running all the other rewite tests on it if (-f $request_filename) { break; }
# check for index.html for directory index # if its there on the filesystem then rewite # the url to add /index.html to the end of it # and then break to send it to the next config rules. if (-f $request_filename/index.html) { rewrite (.*) $1/index.html break; }
# this is the meat of the rails page caching config # it adds .html to the end of the url and then checks # the filesystem for that file. If it exists, then we # rewite the url to have explicit .html on the end # and then send it on its way to the next config rule. # if there is no file on the fs then it sets all the # necessary headers and proxies to our upstream mongrels if (-f $request_filename.html) { rewrite (.*) $1.html break; }
if (!-f $request_filename) { proxy_pass http://mongrel; break; } }
error_page 500 502 503 504 /500.html; error_page 413 /413.html; location = /500.html { root /var/www/www.mydomain.com/current/public; } }
One thing I did happen to notice as well, is if I do performance testing on SSL with httperf, at first it is decently fast, but on many sequential runs it consistently degrades until httperf can barely do any requests. However, even while I do an httperf I can use the SSL version of the site with different computers. It just hangs on some, usually towards the end of the day.
Any ideas?
Thanks, Curtis







