Author |
|
mmfarooq@live.com
Joined: 01 Jan 2016 Posts: 18 Location: lahore
|
Posted: Fri 01 Jan '16 11:30 Post subject: SSL handshake taking too long |
|
|
Hello!
I have installed apache2 with ssl on centos. my application taking too long in ssl conenction in browser. please guide |
|
Back to top |
|
James Blond Moderator

Joined: 19 Jan 2006 Posts: 7407 Location: EU, Germany, Next to Hamburg
|
Posted: Fri 01 Jan '16 12:49 Post subject: |
|
|
In any browser?
How did you install the SSL Cert? |
|
Back to top |
|
mmfarooq@live.com
Joined: 01 Jan 2016 Posts: 18 Location: lahore
|
Posted: Fri 01 Jan '16 14:00 Post subject: |
|
|
yes any broswer.
got the ssl from Authority and place .crt and .key files on the path menioned in .conf file |
|
Back to top |
|
maba

Joined: 05 Feb 2012 Posts: 64 Location: Germany, Heilbronn
|
Posted: Fri 01 Jan '16 21:15 Post subject: |
|
|
Still very little detail.
How long is too long? How does it compare to the same setup without SSL?
It might be a problem with DNS. It is important for SSL that DNS is resolving both the A and the PTR record properly. |
|
Back to top |
|
mmfarooq@live.com
Joined: 01 Jan 2016 Posts: 18 Location: lahore
|
Posted: Fri 01 Jan '16 22:35 Post subject: |
|
|
We are not using without ssl.We are using node and php in apache. browser shows It takes around 900ms in ssl hand shake.
want to show u the screenshot, how can i attach? |
|
Back to top |
|
James Blond Moderator

Joined: 19 Jan 2006 Posts: 7407 Location: EU, Germany, Next to Hamburg
|
Posted: Sat 02 Jan '16 22:27 Post subject: |
|
|
mmfarooq@live.com wrote: |
want to show u the screenshot, how can i attach? |
Google for image hosting upload your image and post the url to that image here. |
|
Back to top |
|
mmfarooq@live.com
Joined: 01 Jan 2016 Posts: 18 Location: lahore
|
|
Back to top |
|
jraute

Joined: 13 Sep 2013 Posts: 188 Location: Rheinland, Germany
|
Posted: Mon 04 Jan '16 8:38 Post subject: |
|
|
What kind of keysize? (2048 or 4096 ... ?) |
|
Back to top |
|
mmfarooq@live.com
Joined: 01 Jan 2016 Posts: 18 Location: lahore
|
Posted: Mon 04 Jan '16 8:54 Post subject: |
|
|
Jraute key size is 2048.. |
|
Back to top |
|
jraute

Joined: 13 Sep 2013 Posts: 188 Location: Rheinland, Germany
|
Posted: Mon 04 Jan '16 12:53 Post subject: |
|
|
Is only the handshake taking that long and afterwards it is fast or does it take that time for every request?
Have a look at http://unmitigatedrisk.com/?p=234
(Between 500ms and 1000ms can be very normal depending on the infrastructure.) |
|
Back to top |
|
mmfarooq@live.com
Joined: 01 Jan 2016 Posts: 18 Location: lahore
|
Posted: Mon 04 Jan '16 13:47 Post subject: |
|
|
after ssl call, it looks good, really fast. every SSL call is taking too much time. |
|
Back to top |
|
jraute

Joined: 13 Sep 2013 Posts: 188 Location: Rheinland, Germany
|
Posted: Mon 04 Jan '16 16:18 Post subject: |
|
|
i've just checked the response time for one of our webservers and i have to say that the ocsp-request to globalsign with 597ms causes most of the time.
So in your case 800ms are maybe very normal.
Have in mind that in case of servers behind a company firewall (for example in a dmz) response times can be increased. |
|
Back to top |
|
James Blond Moderator

Joined: 19 Jan 2006 Posts: 7407 Location: EU, Germany, Next to Hamburg
|
Posted: Mon 04 Jan '16 17:53 Post subject: |
|
|
You can try SSLStaplingCache
Code: | SSLUseStapling On
SSLSessionCache shmcb:/opt/apache2/logs/ssl_gcache_data(512000)
SSLStaplingCache shmcb:/opt/apache2/logs/ssl_stapling_data(512000)
# the default is 600 what is way too long
SSLStaplingErrorCacheTimeout 2
|
|
|
Back to top |
|
mmfarooq@live.com
Joined: 01 Jan 2016 Posts: 18 Location: lahore
|
Posted: Tue 05 Jan '16 15:28 Post subject: |
|
|
ssl ache entries in my ssl.conf is
SSLSessionCache shmcb:/var/cache/mod_ssl/scache(512000)
SSLSessionCacheTimeout 300 |
|
Back to top |
|
jraute

Joined: 13 Sep 2013 Posts: 188 Location: Rheinland, Germany
|
Posted: Tue 05 Jan '16 17:05 Post subject: |
|
|
Caching does not mean that stapling is on.
Look at the code James Blond provided.
For stapling you need
Code: | SSLUseStapling On
SSLStaplingCache shmcb:/opt/apache2/logs/ssl_stapling_data(512000) |
|
|
Back to top |
|
mmfarooq@live.com
Joined: 01 Jan 2016 Posts: 18 Location: lahore
|
Posted: Thu 07 Jan '16 14:30 Post subject: |
|
|
HTTP Server Header: Apache/2.2.29 (Amazon)
using this apche version SSLUseStapling is not being configured thows some syntax error. I did some troubleshoot alot but couldnt find that syntax error.
i m workin gon ec2 instnace.
SSLUseStapling On |
|
Back to top |
|
jraute

Joined: 13 Sep 2013 Posts: 188 Location: Rheinland, Germany
|
Posted: Thu 07 Jan '16 16:13 Post subject: |
|
|
Sorry, Apache supports OCSP stapling in Apache HTTPD Server since version 2.3.3. |
|
Back to top |
|