# TLS ServerName extension during ssl-hello-chk

**URL:** <https://discourse.haproxy.org/t/tls-servername-extension-during-ssl-hello-chk/787>\
**Category:** Help!\
**Created:** [November 7, 2016, 10:30pm UTC](https://discourse.haproxy.org/t/tls-servername-extension-during-ssl-hello-chk/787 "2016-11-07T22:30:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jnitecki](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jnitecki](https://discourse.haproxy.org/u/jnitecki)\
**Post date:** [November 7, 2016, 10:30pm UTC](https://discourse.haproxy.org/t/tls-servername-extension-during-ssl-hello-chk/787/1 "2016-11-07T22:30:48Z")

</div>

Hello,

My backend server requires servername extension to be included during _ClientHello_ message. I’m using transparent load balancing via HAProxy and it works, but health checks can run only in tcp mode. Enabling **ssl-hello-check** fails as no server name extension is provided and server closes connection without responding with _ServerHello_.

Following OpenSSL commands can be used to illustrate what I need:  
**openssl s\_client -servername x.y.z -connect a.b.c.d:443** WORKS  
**openssl s\_client -connect a.b.c.d:443** FAILS HANDSHAKE identically to HAProxy ssl-hello-check

What option shall I use in HAProxy to make it work? I’m using version 1.5.14

Jan

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [November 21, 2016, 5:53pm UTC](https://discourse.haproxy.org/t/tls-servername-extension-during-ssl-hello-chk/787/2 "2016-11-21T17:53:16Z")

</div>

In haproxy 1.6 release we can send a certain SNI value, but not when health checking:

> [@Can 1.6 do SNI on backend?](http://discourse.haproxy.org/t/can-1-6-do-sni-on-backend/278/12):
>
> Thanks for the clarification. I was so focused on the health checks failing that I did not consider that it would work without the health check. I’ll document this thread and issue a ticket. –Ray

You will have to use an external check for this:  
[https://cbonte.github.io/haproxy-dconv/1.6/configuration.html#external-check%20(Process%20management%20and%20security)](https://cbonte.github.io/haproxy-dconv/1.6/configuration.html#external-check%20%28Process%20management%20and%20security%29)

---

<div class="post-metadata">

**Author:** ![rgacote](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/rgacote/32/71_2.png) [@rgacote](https://discourse.haproxy.org/u/rgacote)\
**Post date:** [November 21, 2016, 6:22pm UTC](https://discourse.haproxy.org/t/tls-servername-extension-during-ssl-hello-chk/787/3 "2016-11-21T18:22:49Z")

</div>

Thanks for the update on this.  
I look forward to exploring the external health check functionality.
