# Allow only specific path url with 443/cert

**URL:** <https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174>\
**Category:** Help!\
**Created:** [October 27, 2023, 8:45am UTC](https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174 "2023-10-27T08:45:35Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![antronis](https://avatars.discourse-cdn.com/v4/letter/a/ea5d25/32.png) [@antronis](https://discourse.haproxy.org/u/antronis)\
**Post date:** [October 27, 2023, 8:45am UTC](https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174/1 "2023-10-27T08:45:35Z")

</div>

hello  
i was search already whole day how to work this but have not found any solution.  
have enviroment where haproxy have url that using certificte on ngnix on backend server, so connection is go : internet\>haproxyurl:443\>ngnix&cert, what i need is to setup with mode tcp as http/80 is redirected to https the suffixes paths allow/deny  
so lets say my front looks like that:  
frontend tcp-in-443  
bind 0.0.0.0:443 interface eth0  
mode tcp  
#option tcplog  
maxconn 500  
tcp-request inspect-delay 5s  
tcp-request content accept if { req\_ssl\_hello\_type 1 }  
default\_backend no\_ssl

```
    use_backend xxx.xxx.com if { req_ssl_sni -i xxx.xxx.com }

```

backend [xxx.xxx.com](http://xxx.xxx.com)  
mode tcp  
option tcplog  
server default 123.123.123.123:443 check

what i need is that if someone as sending req to open [xxx.xxx.com](http://xxx.xxx.com) he can he gets 404 or redirection, the ONLY path that can be accessable is [xxx.xxx.com/test/test2/\*](http://xxx.xxx.com/test/test2/*) and not [xxx.xxx.com](http://xxx.xxx.com) or some /blah.  
how i can achive that ? in front ACLs + use\_backed ? i was trying that but was not working or mby i did wrong config…

edit - also this web should be ALL visible from internal LAN that is going to ngnix direct so the idea is to block it only from internet

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 27, 2023, 9:04am UTC](https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174/2 "2023-10-27T09:04:07Z")

</div>

You cannot review/reject/redirect anything on port 443, unless you are actually decrypting it (certificate on haproxy), because you the payload is encrypted otherwise.

On port 80, you can do what you want, use ACL rules to redirect as you please.

---

<div class="post-metadata">

**Author:** ![antronis](https://avatars.discourse-cdn.com/v4/letter/a/ea5d25/32.png) [@antronis](https://discourse.haproxy.org/u/antronis)\
**Post date:** [October 27, 2023, 9:13am UTC](https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174/3 "2023-10-27T09:13:53Z")

</div>

cant do something like this but with /paths ? so the first request that someone is doing from outside will allow him to get to url [xxx.xxx.com/path](http://xxx.xxx.com/path), and if he will put [xxx.xxx.com](http://xxx.xxx.com) haproxy will reject it.

```auto
acl is_host_com hdr(Host) -i example.com
tcp-request inspect-delay 30s
tcp-request content accept if is_host_com
tcp-request content reject

```

so lets say that i can put cert wildcard on haproxy, then its possible to decrypt and allow/reject flow to particular path?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 27, 2023, 9:21am UTC](https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174/4 "2023-10-27T09:21:44Z")

</div>

> [@antronis](#):
>
> cant do something like this but with /paths ?

No, because it is encrypted.

> [@antronis](#):
>
> so lets say that i can put cert wildcard on haproxy, then its possible to decrypt and allow/reject flow to particular path?

Yes.

---

<div class="post-metadata">

**Author:** ![antronis](https://avatars.discourse-cdn.com/v4/letter/a/ea5d25/32.png) [@antronis](https://discourse.haproxy.org/u/antronis)\
**Post date:** [October 27, 2023, 10:01am UTC](https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174/5 "2023-10-27T10:01:42Z")

</div>

something like that ?

frontend xxx.xxx.com-443  
bind 127.0.0.1:443 ssl crt /etc/ssl/certs/wildcard.pem  
mode tcp  
option tcplog  
maxconn 500  
tcp-request inspect-delay 5s  
default\_backend [xxx.xxx.com](http://xxx.xxx.com)

backend [xxx.xxx.com](http://xxx.xxx.com)  
mode http  
cookie SERVERID insert indirect nocache  
option forwardfor  
server default 10.123.123.123:443 check

and with some

```auto
acl path_ok path_beg /test
http-request deny unless path_ok

```

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 27, 2023, 10:49am UTC](https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174/6 "2023-10-27T10:49:09Z")

</div>

You also need `mode http` in the frontend and you need to add “ssl verify none” in the backend server, with enables SSL encryption on the backend and disables certificate verification (unsecure, configure it properly with ssl certificate validation in production).

---

<div class="post-metadata">

**Author:** ![randomguy](https://avatars.discourse-cdn.com/v4/letter/r/ba8739/32.png) [@randomguy](https://discourse.haproxy.org/u/randomguy)\
**Post date:** [October 27, 2023, 9:06pm UTC](https://discourse.haproxy.org/t/allow-only-specific-path-url-with-443-cert/9174/7 "2023-10-27T21:06:48Z")

</div>

About the only differentiator you have at the SSL layer is the SNI (server name identification) which is an extension where the client sends that in their request. The information about what path they want doesn’t exist until after the SSL handshake takes place. (SSL first then HTTP)

So either the data needs to be decrypted by performing the ssl handshake on the haproxy device or you only act on the server name alone. I’d suggest what lukastribus says and that’s to move your cert and key over to the HAPRoxy device. Let it handle the ssl handshake and then allow or reject as needed from there.

You can even do some interesting mapping of hostnames and such to different backends like one user did over here: [How does the SNI Routing works in HAProxy • ME2Digital](https://www.me2digital.com/blog/2019/05/haproxy-sni-routing/)
