#1052613 Keepalived occasionally fails SSL_CHECK

Package:
keepalived
Source:
keepalived
Description:
Failover and monitoring daemon for LVS clusters
Submitter:
Pavel Matěja
Date:
2023-10-04 09:39:03 UTC
Severity:
normal
#1052613#5
Date:
2023-09-25 10:48:54 UTC
From:
To:
I'm upgrading our servers from Bullseye to Bookworm. Some of them act as load balancers using keepalived.
Right now I have one Bullseye and one Bookworm with the same configuration checking the same services.
Several of our services are running on HTTPS therefore I'm using SSL_CHECK.
I can see that the Bookworm one occasionally fails SSL_CHECK for several seconds on one service while the
Bullseye does not report any problem at all.
It's quite rare - not even once per hour with 2s loop delay.

I was looking for possible reason and I've found
https://github.com/openssl/openssl/issues/20365
https://github.com/pjsip/pjproject/issues/3632
https://stackoverflow.com/questions/18179128/how-to-manage-the-error-queue-in-openssl-ssl-get-error-and-err-get-error

They are all basically saying that you can have multiple SSL errors left in error queue and you are supposed to
run|ERR_get_error() before calling |SSL_* functions.

I've tried to patch keepalived sources (see attachment) and the problem seems to disappear.

I have no idea why is Bullseye package unaffected. It might be related to different OpenSSL version.

What do you think about this?

#1052613#10
Date:
2023-10-04 09:34:38 UTC
From:
To:
Hello Pavel,

I'll be more comfortable if you submitted this patch upstream first.