[stunnel-users] Question about "forground = yes" and "output = FILE" combined options

Michael Gebis mgebis at countertack.com
Wed Oct 14 23:21:32 CEST 2015

Maybe you'll indulge me and let me make a final argument in favor of
making a control widget that allows us to run in "foreground" but have
the messages only go to a file.

The reason for this request: We're wrapping stunnel startup for
inclusion as a custom Cloudera service--we want to be able to control
stunnel startup/shutdown/restart through the Cloudera management
tools.  The Cloudera control script "glue" requires that processes run
in the foreground.  This is because they use supervisord which
requires the stunnel process to be rooted under supervisord's process

So we are in the position of having to use "foreground = true".

However, the Cloudera service also captures all of the stderr/stdout
of the managed process, and makes this available through the Cloudera
management console.  If this output is just errors/startup/shutdown
messages, that's about the right volume of messages, but we have a
very busy stunnel with lots of connections, and the Cloudera UI
quickly chokes on the volume of text.

Our current setup redirects stdout/stderr to /dev/null to avoid
overwhelming the Cloudera UI.  But this means that errors during
startup (such as a bad config file) are not available through the
Cloudera interface.  We are living with this right now, and it's not
terrible, but I figured I might as well share my wishlist. :)

I understand that our use case may be rather obscure, and are probably
outside the scope of what you would like to do with stunnel.  But I
just wanted to explain.  Thanks for reading!

On Wed, Oct 14, 2015 at 1:34 PM, Michael Gebis <mgebis at countertack.com> wrote:
> Michal,
> Thank you for the speedy response!
> Michael
> On Wed, Oct 14, 2015 at 1:19 PM, Michal Trojnara
> <Michal.Trojnara at mirt.net> wrote:
>> Hash: SHA256
>> On 14.10.2015 21:42, Michael Gebis wrote:
>>> I have a question about the combination of the "foreground = yes"
>>> option combined with the "output = FILE" option.
>> [cut]
>>> This implies that if you set both "foreground = yes" and "output =
>>> FILE", the log messages will not be sent to stderr and will instead
>>> be sent to the log file only.
>> The implementation was modified in version 4.22 to allow logging to
>> multiple destinations, but apparently I never updated the manual to
>> reflect this change.
>>> We'd like this behavior--it makes it easier for our scripts to
>>> distinguish startup errors parsing the config file (which are sent
>>> to stderr, since the log file isn't configured yet) vs. normal
>>> operation after the config file is parsed and the log file is
>>> established.
>> This is close to the way it works without "foreground = yes".
>>> I guess I'm asking: is the documentation in conflict with the
>>> behavior, and if so, which is correct?
>> The software works as intended.  I need to update the documentation.
>> Best regards,
>>         Mike
>> Version: GnuPG v2
>> Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
>> GVgJdeZn5wRlsoE/p6rCoFJ9+7vgw0Rh/7pIWKkzgoDfVDRDI2/TUlV0SPBJyyQw
>> jY9F4M82QP3vIJSGYmJF2AWcZEY0z+Mc17Bm+HIvqiUIBmzMS+5N/O+4u/rZr0SO
>> yibtfpowjAnqA3cNAZNJkhncjmc3GbsXqsYOvIUoZhNzoaOML0RC6DBrPLFhZQ+w
>> ZiMUPRByR17sX37uuy8fBRph62tvU2a+mON1AuozW0dZvdjPNnxXYsIdHbOkS1CK
>> XSQWlHVkBar/gUoHbN8AEkBTFl90FQI1y5sTVJqYpEb/ciy8gL5Eo1ZuhM2/RDPN
>> mncB1Pe8H0kBDxzOGcdwppk4+qj2jEPKRm3KhivO+Jwq0bpgmprMecWsUrvGxojL
>> N+kPcPSW14JIeZOWhSrf706fAUSmQQOTxkuXD1mfpxlkW/gVUwAiI4Vceo8i6f/1
>> uQ86g7oJlYaqz5g3cqAOxT4+uwgp1UEtBbsb2rq0K848IYFlK5fVFTkjxl06iGKF
>> NvTUCdXdLmXNP3nYZu2lo67owCqsROOrA5oh83cCf6s5zMqAd7eErUeeWi25fooK
>> Lu3dwlit/2KWwnjeR2f3
>> =OaRE
>> -----END PGP SIGNATURE-----
>> _______________________________________________
>> stunnel-users mailing list
>> stunnel-users at stunnel.org
>> https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users

More information about the stunnel-users mailing list