<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Stunnel - Future plans to use something else?]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">Im wondering if there is any official roadmap where the deprecation of stunnel is included?<br />
If yes, what is the planned replacement for this since XAPI doesnt support native SSL communicatio?</p>
<p dir="auto">BR N</p>
]]></description><link>https://xcp-ng.org/forum/topic/8424/stunnel-future-plans-to-use-something-else</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Apr 2026 14:03:14 GMT</lastBuildDate><atom:link href="https://xcp-ng.org/forum/topic/8424.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 20 Feb 2024 10:34:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Mon, 26 Feb 2024 14:35:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/psafont" aria-label="Profile: psafont">@<bdi>psafont</bdi></a> said in <a href="/forum/post/72191">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nikade" aria-label="Profile: nikade">@<bdi>nikade</bdi></a> We've already fixed some issues to start using ocaml 5 regarding the C interfaces. Handling threading in ocaml 5 is still an open problem that the ecosystem has not yet solved (there are many libraries competing now). We still need to create a credible strategy to port xapi to the new model, and don't have any timelines yet</p>
</blockquote>
<p dir="auto">Yea porting it is probably not a bad idea, but I guess that involves the biggest tasks as well <img src="https://xcp-ng.org/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=a78c449d9ac" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /><br />
All tho if you port it there might be opportunities to re-do a lot of things that you have been looking to fix for ages.</p>
<p dir="auto">Crossing my fingers that this is something that you get time to do in the near future, there is a real chance here to take a big part of the esxi market as a lot of ppl are migrating.</p>
]]></description><link>https://xcp-ng.org/forum/post/72198</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/72198</guid><dc:creator><![CDATA[nikade]]></dc:creator><pubDate>Mon, 26 Feb 2024 14:35:46 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Mon, 26 Feb 2024 12:56:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nikade" aria-label="Profile: nikade">@<bdi>nikade</bdi></a> We've already fixed some issues to start using ocaml 5 regarding the C interfaces. Handling threading in ocaml 5 is still an open problem that the ecosystem has not yet solved (there are many libraries competing now). We still need to create a credible strategy to port xapi to the new model, and don't have any timelines yet</p>
]]></description><link>https://xcp-ng.org/forum/post/72191</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/72191</guid><dc:creator><![CDATA[psafont]]></dc:creator><pubDate>Mon, 26 Feb 2024 12:56:35 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 18:01:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/psafont" aria-label="Profile: psafont">@<bdi>psafont</bdi></a> said in <a href="/forum/post/71912">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto">@john-c This involves waiting on a stable OCaml 5 version being release, then porting the whole codebase to use the new multithreading APIs, this is a very complex matter, and it will take a long time until it's realised</p>
</blockquote>
<p dir="auto">Is there any plans on that or is it already on some kind of roadmap?</p>
]]></description><link>https://xcp-ng.org/forum/post/71927</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71927</guid><dc:creator><![CDATA[nikade]]></dc:creator><pubDate>Wed, 21 Feb 2024 18:01:10 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 16:56:50 GMT]]></title><description><![CDATA[<p dir="auto">And there's maybe easier bottleneck to fix before <img src="https://xcp-ng.org/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=a78c449d9ac" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://xcp-ng.org/forum/post/71915</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71915</guid><dc:creator><![CDATA[olivierlambert]]></dc:creator><pubDate>Wed, 21 Feb 2024 16:56:50 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 16:49:37 GMT]]></title><description><![CDATA[<p dir="auto">@john-c This involves waiting on a stable OCaml 5 version being release, then porting the whole codebase to use the new multithreading APIs, this is a very complex matter, and it will take a long time until it's realised</p>
]]></description><link>https://xcp-ng.org/forum/post/71912</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71912</guid><dc:creator><![CDATA[psafont]]></dc:creator><pubDate>Wed, 21 Feb 2024 16:49:37 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 15:46:35 GMT]]></title><description><![CDATA[<p dir="auto">I think it's a pretty complex issue, but I'm not a XAPI dev, so I can't answer <img src="https://xcp-ng.org/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=a78c449d9ac" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://xcp-ng.org/forum/post/71890</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71890</guid><dc:creator><![CDATA[olivierlambert]]></dc:creator><pubDate>Wed, 21 Feb 2024 15:46:35 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 16:43:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> said in <a href="/forum/post/71883">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto">So it doesn't seem to be an issue: XAPI will spawn multiple stunnel process if needed. XAPI itself is not multithreaded, so the bottleneck might not be stunnel after all.</p>
</blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/psafont" aria-label="Profile: psafont">@<bdi>psafont</bdi></a> Maybe worth multithreading the XAPI to help its performance, so that when going through stunnel it doesn't act as a bottleneck.</p>
]]></description><link>https://xcp-ng.org/forum/post/71884</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71884</guid><dc:creator><![CDATA[john.c]]></dc:creator><pubDate>Wed, 21 Feb 2024 16:43:46 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 15:00:14 GMT]]></title><description><![CDATA[<p dir="auto">So it doesn't seem to be an issue: XAPI will spawn multiple stunnel process if needed. XAPI itself is not multithreaded, so the bottleneck might not be stunnel after all.</p>
]]></description><link>https://xcp-ng.org/forum/post/71883</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71883</guid><dc:creator><![CDATA[olivierlambert]]></dc:creator><pubDate>Wed, 21 Feb 2024 15:00:14 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 15:04:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/jeffberntsen" aria-label="Profile: JeffBerntsen">@<bdi>JeffBerntsen</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/psafont" aria-label="Profile: psafont">@<bdi>psafont</bdi></a> Additionally it may be worth making sure it's at least version 5.70 though much better and preferred to be version 5.72. As this new version has several major bug and vulnerabilities fixed.</p>
<p dir="auto"><a href="https://www.stunnel.org/NEWS.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/NEWS.html</a></p>
]]></description><link>https://xcp-ng.org/forum/post/71880</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71880</guid><dc:creator><![CDATA[john.c]]></dc:creator><pubDate>Wed, 21 Feb 2024 15:04:11 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 14:38:32 GMT]]></title><description><![CDATA[<p dir="auto">I'm not sure about 8.3 but I'm pretty sure that hasn't changed since 8.2.1.</p>
<p dir="auto">Using ldd on 8.2.1's stunnel binary shows dependencies on  libpthread and libwrap so I'm guessing it was compiled with thread and wrapper support.</p>
]]></description><link>https://xcp-ng.org/forum/post/71879</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71879</guid><dc:creator><![CDATA[JeffBerntsen]]></dc:creator><pubDate>Wed, 21 Feb 2024 14:38:32 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 14:35:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> said in <a href="/forum/post/71874">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto">IDK and that's why I invoked <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/psafont" aria-label="Profile: psafont">@<bdi>psafont</bdi></a> <img src="https://xcp-ng.org/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61b.png?v=a78c449d9ac" class="not-responsive emoji emoji-android emoji--stuck_out_tongue" style="height:23px;width:auto;vertical-align:middle" title=":p" alt="😛" /></p>
</blockquote>
<p dir="auto">Alright!<br />
This might actually be a big deal if its single threaded and you guys are able to bundle one that is multithreaded in the base XCP-NG installation.<br />
Crossing my fingers over here!</p>
]]></description><link>https://xcp-ng.org/forum/post/71878</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71878</guid><dc:creator><![CDATA[nikade]]></dc:creator><pubDate>Wed, 21 Feb 2024 14:35:37 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 14:04:09 GMT]]></title><description><![CDATA[<p dir="auto">IDK and that's why I invoked <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/psafont" aria-label="Profile: psafont">@<bdi>psafont</bdi></a> <img src="https://xcp-ng.org/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61b.png?v=a78c449d9ac" class="not-responsive emoji emoji-android emoji--stuck_out_tongue" style="height:23px;width:auto;vertical-align:middle" title=":p" alt="😛" /></p>
]]></description><link>https://xcp-ng.org/forum/post/71874</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71874</guid><dc:creator><![CDATA[olivierlambert]]></dc:creator><pubDate>Wed, 21 Feb 2024 14:04:09 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Wed, 21 Feb 2024 10:25:47 GMT]]></title><description><![CDATA[<p dir="auto">@john-c said in <a href="/forum/post/71853">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nikade" aria-label="Profile: nikade">@<bdi>nikade</bdi></a> said in <a href="/forum/post/71842">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto">@john-c said in <a href="/forum/post/71833">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nikade" aria-label="Profile: nikade">@<bdi>nikade</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> The stunnel software isn't just single threaded it is capable of multithreading already. The functionality of it depends on how stunnel is compiled, then configured for use afterwards.</p>
<p dir="auto">The following requirements need to be met:-</p>
<ul>
<li>Compiled with thread support</li>
<li>Create or edit your stunnel configuration file</li>
<li>Ensure that the configuration file includes at least the section name and accept option.</li>
<li>Running stunnel in daemon mode over inetd mode</li>
<li>Optionally include TCPWrappers support when compiling or using pre compiled packages.</li>
<li>Ensure libwrap library is installed (stunnel will use lwrap when present)</li>
<li>Specify the allowed machines in /etc/hosts.allow in the following format:</li>
</ul>
<p dir="auto">service1: <a href="http://goodhost1.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">goodhost1.example.com</a> .trusteddomain.example.com<br />
service2: <a href="http://goodhost2.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">goodhost2.example.com</a> 192.168.0.50</p>
<ul>
<li>Restarting stunnel (if running as a daemon already) or stopping and then starting again.</li>
</ul>
<p dir="auto"><a href="https://www.stunnel.org/howto.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/howto.html</a><br />
<a href="https://ipcamtalk.com/threads/stunnel-can-be-a-multi-host-incoming-router.36710/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ipcamtalk.com/threads/stunnel-can-be-a-multi-host-incoming-router.36710/</a><br />
<a href="https://stackoverflow.com/questions/54450367/stunnel-two-ubuntu-machines-traffic-encryption" target="_blank" rel="noopener noreferrer nofollow ugc">https://stackoverflow.com/questions/54450367/stunnel-two-ubuntu-machines-traffic-encryption</a><br />
<a href="https://www.stunnel.org/config_windows.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/config_windows.html</a><br />
<a href="https://www.stunnel.org/faq.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/faq.html</a><br />
<a href="https://superuser.com/questions/503553/how-to-properly-use-stunnel" target="_blank" rel="noopener noreferrer nofollow ugc">https://superuser.com/questions/503553/how-to-properly-use-stunnel</a><br />
<a href="https://www.stunnel.org/config_unix.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/config_unix.html</a><br />
<a href="https://www.stunnel.org/perf.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/perf.html</a></p>
</blockquote>
<p dir="auto">Great feedback, thanks!<br />
Do you think that this is something that could be done in the base configuration to enable better performance or is it just bandage on the problem?</p>
<p dir="auto">BR N</p>
</blockquote>
<p dir="auto">It's done on a per service basis, though parts may be able to be in the base configuration. Each of those when put together enables the stunnel's multithreading, but only if the stunnel has been compiled at minimum with the thread option.</p>
<p dir="auto">So if you are using a precompiled binary which has been packaged for your distribution, then it will need to have been compiled with the thread option before being packaged. Though it can be compiled from source with that option, though if receiving support best see if the people who are providing the support (for the distro) can provide a version with it.</p>
</blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> Do you know if it is still compiled as single threaded in XCP-NG 8.3?</p>
]]></description><link>https://xcp-ng.org/forum/post/71866</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71866</guid><dc:creator><![CDATA[nikade]]></dc:creator><pubDate>Wed, 21 Feb 2024 10:25:47 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Tue, 20 Feb 2024 21:52:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nikade" aria-label="Profile: nikade">@<bdi>nikade</bdi></a> said in <a href="/forum/post/71842">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto">@john-c said in <a href="/forum/post/71833">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nikade" aria-label="Profile: nikade">@<bdi>nikade</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> The stunnel software isn't just single threaded it is capable of multithreading already. The functionality of it depends on how stunnel is compiled, then configured for use afterwards.</p>
<p dir="auto">The following requirements need to be met:-</p>
<ul>
<li>Compiled with thread support</li>
<li>Create or edit your stunnel configuration file</li>
<li>Ensure that the configuration file includes at least the section name and accept option.</li>
<li>Running stunnel in daemon mode over inetd mode</li>
<li>Optionally include TCPWrappers support when compiling or using pre compiled packages.</li>
<li>Ensure libwrap library is installed (stunnel will use lwrap when present)</li>
<li>Specify the allowed machines in /etc/hosts.allow in the following format:</li>
</ul>
<p dir="auto">service1: <a href="http://goodhost1.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">goodhost1.example.com</a> .trusteddomain.example.com<br />
service2: <a href="http://goodhost2.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">goodhost2.example.com</a> 192.168.0.50</p>
<ul>
<li>Restarting stunnel (if running as a daemon already) or stopping and then starting again.</li>
</ul>
<p dir="auto"><a href="https://www.stunnel.org/howto.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/howto.html</a><br />
<a href="https://ipcamtalk.com/threads/stunnel-can-be-a-multi-host-incoming-router.36710/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ipcamtalk.com/threads/stunnel-can-be-a-multi-host-incoming-router.36710/</a><br />
<a href="https://stackoverflow.com/questions/54450367/stunnel-two-ubuntu-machines-traffic-encryption" target="_blank" rel="noopener noreferrer nofollow ugc">https://stackoverflow.com/questions/54450367/stunnel-two-ubuntu-machines-traffic-encryption</a><br />
<a href="https://www.stunnel.org/config_windows.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/config_windows.html</a><br />
<a href="https://www.stunnel.org/faq.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/faq.html</a><br />
<a href="https://superuser.com/questions/503553/how-to-properly-use-stunnel" target="_blank" rel="noopener noreferrer nofollow ugc">https://superuser.com/questions/503553/how-to-properly-use-stunnel</a><br />
<a href="https://www.stunnel.org/config_unix.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/config_unix.html</a><br />
<a href="https://www.stunnel.org/perf.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/perf.html</a></p>
</blockquote>
<p dir="auto">Great feedback, thanks!<br />
Do you think that this is something that could be done in the base configuration to enable better performance or is it just bandage on the problem?</p>
<p dir="auto">BR N</p>
</blockquote>
<p dir="auto">It's done on a per service basis, though parts may be able to be in the base configuration. Each of those when put together enables the stunnel's multithreading, but only if the stunnel has been compiled at minimum with the thread option.</p>
<p dir="auto">So if you are using a precompiled binary which has been packaged for your distribution, then it will need to have been compiled with the thread option before being packaged. Though it can be compiled from source with that option, though if receiving support best see if the people who are providing the support (for the distro) can provide a version with it.</p>
]]></description><link>https://xcp-ng.org/forum/post/71853</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71853</guid><dc:creator><![CDATA[john.c]]></dc:creator><pubDate>Tue, 20 Feb 2024 21:52:20 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Tue, 20 Feb 2024 21:13:32 GMT]]></title><description><![CDATA[<p dir="auto">@john-c said in <a href="/forum/post/71833">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nikade" aria-label="Profile: nikade">@<bdi>nikade</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> The stunnel software isn't just single threaded it is capable of multithreading already. The functionality of it depends on how stunnel is compiled, then configured for use afterwards.</p>
<p dir="auto">The following requirements need to be met:-</p>
<ul>
<li>Compiled with thread support</li>
<li>Create or edit your stunnel configuration file</li>
<li>Ensure that the configuration file includes at least the section name and accept option.</li>
<li>Running stunnel in daemon mode over inetd mode</li>
<li>Optionally include TCPWrappers support when compiling or using pre compiled packages.</li>
<li>Ensure libwrap library is installed (stunnel will use lwrap when present)</li>
<li>Specify the allowed machines in /etc/hosts.allow in the following format:</li>
</ul>
<p dir="auto">service1: <a href="http://goodhost1.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">goodhost1.example.com</a> .trusteddomain.example.com<br />
service2: <a href="http://goodhost2.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">goodhost2.example.com</a> 192.168.0.50</p>
<ul>
<li>Restarting stunnel (if running as a daemon already) or stopping and then starting again.</li>
</ul>
<p dir="auto"><a href="https://www.stunnel.org/howto.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/howto.html</a><br />
<a href="https://ipcamtalk.com/threads/stunnel-can-be-a-multi-host-incoming-router.36710/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ipcamtalk.com/threads/stunnel-can-be-a-multi-host-incoming-router.36710/</a><br />
<a href="https://stackoverflow.com/questions/54450367/stunnel-two-ubuntu-machines-traffic-encryption" target="_blank" rel="noopener noreferrer nofollow ugc">https://stackoverflow.com/questions/54450367/stunnel-two-ubuntu-machines-traffic-encryption</a><br />
<a href="https://www.stunnel.org/config_windows.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/config_windows.html</a><br />
<a href="https://www.stunnel.org/faq.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/faq.html</a><br />
<a href="https://superuser.com/questions/503553/how-to-properly-use-stunnel" target="_blank" rel="noopener noreferrer nofollow ugc">https://superuser.com/questions/503553/how-to-properly-use-stunnel</a><br />
<a href="https://www.stunnel.org/config_unix.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/config_unix.html</a><br />
<a href="https://www.stunnel.org/perf.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/perf.html</a></p>
</blockquote>
<p dir="auto">Great feedback, thanks!<br />
Do you think that this is something that could be done in the base configuration to enable better performance or is it just bandage on the problem?</p>
<p dir="auto">BR N</p>
]]></description><link>https://xcp-ng.org/forum/post/71842</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71842</guid><dc:creator><![CDATA[nikade]]></dc:creator><pubDate>Tue, 20 Feb 2024 21:13:32 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Tue, 20 Feb 2024 19:26:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nikade" aria-label="Profile: nikade">@<bdi>nikade</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> The stunnel software isn't just single threaded it is capable of multithreading already. The functionality of it depends on how stunnel is compiled, then configured for use afterwards.</p>
<p dir="auto">The following requirements need to be met:-</p>
<ul>
<li>Compiled with thread support</li>
<li>Create or edit your stunnel configuration file</li>
<li>Ensure that the configuration file includes at least the section name and accept option.</li>
<li>Running stunnel in daemon mode over inetd mode</li>
<li>Optionally include TCPWrappers support when compiling or using pre compiled packages.</li>
<li>Ensure libwrap library is installed (stunnel will use lwrap when present)</li>
<li>Specify the allowed machines in /etc/hosts.allow in the following format:</li>
</ul>
<p dir="auto">service1: <a href="http://goodhost1.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">goodhost1.example.com</a> .trusteddomain.example.com<br />
service2: <a href="http://goodhost2.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">goodhost2.example.com</a> 192.168.0.50</p>
<ul>
<li>Restarting stunnel (if running as a daemon already) or stopping and then starting again.</li>
</ul>
<p dir="auto"><a href="https://www.stunnel.org/howto.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/howto.html</a><br />
<a href="https://ipcamtalk.com/threads/stunnel-can-be-a-multi-host-incoming-router.36710/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ipcamtalk.com/threads/stunnel-can-be-a-multi-host-incoming-router.36710/</a><br />
<a href="https://stackoverflow.com/questions/54450367/stunnel-two-ubuntu-machines-traffic-encryption" target="_blank" rel="noopener noreferrer nofollow ugc">https://stackoverflow.com/questions/54450367/stunnel-two-ubuntu-machines-traffic-encryption</a><br />
<a href="https://www.stunnel.org/config_windows.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/config_windows.html</a><br />
<a href="https://www.stunnel.org/faq.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/faq.html</a><br />
<a href="https://superuser.com/questions/503553/how-to-properly-use-stunnel" target="_blank" rel="noopener noreferrer nofollow ugc">https://superuser.com/questions/503553/how-to-properly-use-stunnel</a><br />
<a href="https://www.stunnel.org/config_unix.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/config_unix.html</a><br />
<a href="https://www.stunnel.org/perf.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stunnel.org/perf.html</a></p>
]]></description><link>https://xcp-ng.org/forum/post/71833</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71833</guid><dc:creator><![CDATA[john.c]]></dc:creator><pubDate>Tue, 20 Feb 2024 19:26:49 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Tue, 20 Feb 2024 12:53:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> said in <a href="/forum/post/71758">Stunnel - Future plans to use something else?</a>:</p>
<blockquote>
<p dir="auto">Hmm question for <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/psafont" aria-label="Profile: psafont">@<bdi>psafont</bdi></a> because I think I remember a discussion on how XAPI will support SSL natively in the future (but it's been a while so I could have a bad recollection of this discussion)</p>
</blockquote>
<p dir="auto">This would be a good thing to address - I think it would increase performance a lot since stunnel currently seems to be single-threaded and I often see it maxed out at 100% on our pools.<br />
Atleast get it on the roadmap to make sure there is a long term plan for it, please.</p>
]]></description><link>https://xcp-ng.org/forum/post/71768</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71768</guid><dc:creator><![CDATA[nikade]]></dc:creator><pubDate>Tue, 20 Feb 2024 12:53:00 GMT</pubDate></item><item><title><![CDATA[Reply to Stunnel - Future plans to use something else? on Tue, 20 Feb 2024 10:51:17 GMT]]></title><description><![CDATA[<p dir="auto">Hmm question for <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/psafont" aria-label="Profile: psafont">@<bdi>psafont</bdi></a> because I think I remember a discussion on how XAPI will support SSL natively in the future (but it's been a while so I could have a bad recollection of this discussion)</p>
]]></description><link>https://xcp-ng.org/forum/post/71758</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/71758</guid><dc:creator><![CDATA[olivierlambert]]></dc:creator><pubDate>Tue, 20 Feb 2024 10:51:17 GMT</pubDate></item></channel></rss>