Dear maintainer,
I have found that haproxy (both stable and backported) is unable to load correctly multiple certificate bundles using multicert setups.
The application reports errors loading the certificate chain but I could pinpoint the issue to the way in which dhparams are loaded.
Sadly, this is the only way to provide both an ECDSA and RSA key to connecting users on systems like Debian Stretch where openssl-1.1.1 isn't available.
I have wrotten, compiled and tested the attached patch. I would be very thankful if it could be included on your next backports build.
I have also submitted the patch to upstream for consideration.
I am using Debian 9.0 and the haproxy package from the stretch-backports.
Yours truly,
Francisco Izquierdo (klondike)