Skip to content

RFC: AWS-LC as TLS Backend for HAProxy#1501

Draft
hoffmaen wants to merge 1 commit into
cloudfoundry:mainfrom
sap-contributions:rfc-haproxy-awslc
Draft

RFC: AWS-LC as TLS Backend for HAProxy#1501
hoffmaen wants to merge 1 commit into
cloudfoundry:mainfrom
sap-contributions:rfc-haproxy-awslc

Conversation

@hoffmaen
Copy link
Copy Markdown
Contributor

@hoffmaen hoffmaen commented May 19, 2026

Link to the document for quick review: rfc-draft-haproxy-awslc.md

Summary

This PR adds the RFC for AWS-LC as TLS Backend for the haproxy-boshrelease.

AWS-LC is independent of the version provided via the BOSH stemcell and can be kept up to date interdependently. The OpenSSL that is currently used via the stemcell is on an outdated version that has severe performance impacts in high-load scenarios. These would be improved in newer OpenSSL versions, but not resolved. HAProxy explicitely recommends against OpenSSL in production (haproxy/haproxy#3086).

AWS-LC alleviates these issues and is proposed to be added as an optional release. For operators nothing changes, unless they want to opt into using AWS-LC.

AWS-LC is FIPS 140-3 compliant.

@hoffmaen hoffmaen force-pushed the rfc-haproxy-awslc branch from b0c5b6d to d570aaf Compare May 19, 2026 09:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Inbox

Development

Successfully merging this pull request may close these issues.

1 participant