Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. Spent way too long getting HTTP/3 working on FreeBSD with nginx, so I wrote it all up.

Spent way too long getting HTTP/3 working on FreeBSD with nginx, so I wrote it all up.

Scheduled Pinned Locked Moved Uncategorized
freebsdnginxhttp3quicnetworking
4 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Larvitz :fedora: :redhat:L This user is from outside of this forum
    Larvitz :fedora: :redhat:L This user is from outside of this forum
    Larvitz :fedora: :redhat:
    wrote last edited by
    #1

    Spent way too long getting HTTP/3 working on FreeBSD with nginx, so I wrote it all up.

    The highlights: stock OpenSSL silently breaks QUIC at the HTTP/3 framing layer (the TLS handshake succeeds, so openssl s_client lies to you). eBPF worker routing doesn't exist on FreeBSD. And if nginx is in a jail with IPv4 NAT, a pass rule for UDP 443 is useless without a matching rdr.

    New post: https://blog.hofstede.it/http3-on-freebsd-getting-quic-working-with-nginx-in-a-bastille-jail/

    #FreeBSD #nginx #HTTP3 #QUIC #Networking

    vermadenV James O'GormanJ 2 Replies Last reply
    1
    0
    • R ActivityRelay shared this topic
    • Larvitz :fedora: :redhat:L Larvitz :fedora: :redhat:

      Spent way too long getting HTTP/3 working on FreeBSD with nginx, so I wrote it all up.

      The highlights: stock OpenSSL silently breaks QUIC at the HTTP/3 framing layer (the TLS handshake succeeds, so openssl s_client lies to you). eBPF worker routing doesn't exist on FreeBSD. And if nginx is in a jail with IPv4 NAT, a pass rule for UDP 443 is useless without a matching rdr.

      New post: https://blog.hofstede.it/http3-on-freebsd-getting-quic-working-with-nginx-in-a-bastille-jail/

      #FreeBSD #nginx #HTTP3 #QUIC #Networking

      vermadenV This user is from outside of this forum
      vermadenV This user is from outside of this forum
      vermaden
      wrote last edited by
      #2

      @Larvitz

      Another great article that goes straight to latest Valuable News issue - thank You for writing it 🙂

      Now ... I would probably add least needed and least technical comment here - but that also hit me in the past ... the 'special' ASCII character ... misalign like 9 in 10 times.

      Using 'regular' chars like '|' or '+' instead always aligns these ASCII diagrams well.

      Regards,
      vermaden

      Larvitz :fedora: :redhat:L 1 Reply Last reply
      0
      • vermadenV vermaden

        @Larvitz

        Another great article that goes straight to latest Valuable News issue - thank You for writing it 🙂

        Now ... I would probably add least needed and least technical comment here - but that also hit me in the past ... the 'special' ASCII character ... misalign like 9 in 10 times.

        Using 'regular' chars like '|' or '+' instead always aligns these ASCII diagrams well.

        Regards,
        vermaden

        Larvitz :fedora: :redhat:L This user is from outside of this forum
        Larvitz :fedora: :redhat:L This user is from outside of this forum
        Larvitz :fedora: :redhat:
        wrote last edited by
        #3

        @vermaden Will try that 🙂

        I wrote the article on my real life experience when enabling HTTP/3 on the Mastodon instance, I am managing (https://burningboard.net). I thought it might be interesting for others, since there were some pitfalls and it wasn't just "enabling an option".

        1 Reply Last reply
        1
        0
        • Larvitz :fedora: :redhat:L Larvitz :fedora: :redhat:

          Spent way too long getting HTTP/3 working on FreeBSD with nginx, so I wrote it all up.

          The highlights: stock OpenSSL silently breaks QUIC at the HTTP/3 framing layer (the TLS handshake succeeds, so openssl s_client lies to you). eBPF worker routing doesn't exist on FreeBSD. And if nginx is in a jail with IPv4 NAT, a pass rule for UDP 443 is useless without a matching rdr.

          New post: https://blog.hofstede.it/http3-on-freebsd-getting-quic-working-with-nginx-in-a-bastille-jail/

          #FreeBSD #nginx #HTTP3 #QUIC #Networking

          James O'GormanJ This user is from outside of this forum
          James O'GormanJ This user is from outside of this forum
          James O'Gorman
          wrote last edited by
          #4

          @Larvitz Great write up! One question: do you also have HTTP/2 enabled? The config you listed at the end looks like it would have the client start on 1.1.

          Just curious because I seem to recall Nginx having multiple ways of doing h2.

          1 Reply Last reply
          0
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          Powered by NodeBB Contributors
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups