Erlang Mailing Lists

Author Message

<  RabbitMQ mailing list  ~  RabbitMQ & SSL

Guest
Posted: Mon Dec 24, 2007 2:43 pm Reply with quote
Guest
Howdy,

A few months ago, you all posted about a development version of RabbitMQ with SSL.

Is this going to be a reality in the next few weeks?

If not and I use stunnel, will there be an stunnel process forked for each TCP/IP connection to the server?

How difficult would it be to have the ConnectionParameters/Connection classes to include an SSL flag?
tonyg
Posted: Thu Dec 27, 2007 2:58 pm Reply with quote
User Joined: 07 Nov 2006 Posts: 199
Hi David,

David Pollak wrote:
> A few months ago, you all posted about a development version of RabbitMQ
> with SSL.

Yes. The changes were all in the client. We haven't implemented SSL
support in the server yet - instead, just as a temporary hack, I was
using stunnel4.

(As an aside, SSL support in erlang seems relatively straightforward,
but it was more than the hour I had available. SSL support in Java fit
nicely into the available time, however Smile )

> Is this going to be a reality in the next few weeks?

Yes, we hope to have an official release ready within the next month,
but until then, you could use the Java client code from one of our
unsupported, unofficial snapshots, available at
http://dev.rabbitmq.com/snapshots/rabbitmq/

The most recent one definitely has the SSL changes. (I checked.)

> If not and I use stunnel, will there be an stunnel process forked for
> each TCP/IP connection to the server?

I'm afraid I haven't investigated the details of how stunnel4 works.

Well, I've just had a look Smile and I think stunnel4 can either fork() or
use pthreads, depending on how you build it. I'm not sure which strategy
it was using when I was doing my experiments.

BTW, I had the following entry in my stunnel.conf:

[amqps]
accept = 6035
connect = 5672

I can't remember where I got 6035 from.

> How difficult would it be to have the ConnectionParameters/Connection
> classes to include an SSL flag?

That's almost exactly what we've implemented. Essentially, do the following:

ConnectionFactory connFactory = (however you build and configure one);
connFactory.useSslProtocol();

and it should work.

> If it's hard, do you know if the Apache
> Qpid classes work against RabbitMQ (I know they're supposed to, but is
> there any verification)?

The non-SSL QPid client works against RabbitMQ, up to the point where
QPid's implementation of the protocol diverges from the spec, or
RabbitMQ's implementation of the protocol doesn't implement some of the
JMS-specific pieces.

> David (who will let you know about his Rabbit-based project in mid-January)

Very exciting, I'm looking forward to it Smile

Regards,
Tony
--
[][][] Tony Garnock-Jones | Mob: +44 (0)7905 974 211
[][] LShift Ltd | Tel: +44 (0)20 7729 7060
[] [] http://www.lshift.net/ | Email: tonyg@lshift.net

_______________________________________________
rabbitmq-discuss mailing list
rabbitmq-discuss@lists.rabbitmq.com
http://lists.rabbitmq.com/cgi-bin/mailman/listinfo/rabbitmq-discuss
Post recived from mailinglist
View user's profile Send private message MSN Messenger
tonyg
Posted: Thu Dec 27, 2007 3:00 pm Reply with quote
User Joined: 07 Nov 2006 Posts: 199
Tony Garnock-Jones wrote:
> The non-SSL QPid client works against RabbitMQ, [...]

I guess I should clarify, and state that I haven't tried QPid's SSL
support at all Smile

Regards,
Tony
--
[][][] Tony Garnock-Jones | Mob: +44 (0)7905 974 211
[][] LShift Ltd | Tel: +44 (0)20 7729 7060
[] [] http://www.lshift.net/ | Email: tonyg@lshift.net

_______________________________________________
rabbitmq-discuss mailing list
rabbitmq-discuss@lists.rabbitmq.com
http://lists.rabbitmq.com/cgi-bin/mailman/listinfo/rabbitmq-discuss
Post recived from mailinglist
View user's profile Send private message MSN Messenger
wuji
Posted: Mon Aug 27, 2012 6:32 am Reply with quote
User Joined: 10 Aug 2012 Posts: 654
when I think he's in the wrong profession, because he's he's cheap polo ralph lauren he's very smart, and he's very introspective," said Wirick, who
that even though he's a Democrat, he'll probably vote for for cheap replica *beep* for Romney if Portman was on the ticket. "He's very
You could see him as being a high-ranking attorney in in authentic jordans in the Justice Department or something. He approaches things very,
thoughtfully."Social conservatives and members of the tea party who made made [h4]real jordans[/h4] made Romney's life tough for the past few months, by
to the more right-wing Rick Santorum are hoping that the the imitation designer *beep* the nominee-to-be picks someone in their camp to run on
View user's profile Send private message

Display posts from previous:  

All times are GMT
Page 1 of 1
This forum is locked: you cannot post, reply to, or edit topics.

Jump to:  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum