# HAProxy, single domain name, multiple subdomains with SSL

**URL:** <https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117>\
**Category:** Help!\
**Created:** [October 20, 2018, 2:55pm UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117 "2018-10-20T14:55:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![PunkIsDaFunk](https://avatars.discourse-cdn.com/v4/letter/p/77aa72/32.png) [@PunkIsDaFunk](https://discourse.haproxy.org/u/PunkIsDaFunk)\
**Post date:** [October 20, 2018, 2:55pm UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/1 "2018-10-20T14:55:59Z")

</div>

I am trying to setup a farm of servers to serve the same website across all the servers, including the subdomains. I posted my example configuration below.

When tested it seemed to allow for the main website to be loaded, but anytime the subdomains were accessed it would just redirect to the main domain’s content. Is there a way using the configuration I have below, or some other configuration, and I can accomplish the goal of having say 4 servers, all serving the same root domain and subdomains, while still utilizing an SSL certificate for all traffic? Each website also contains a 301 redirect to HTTPS to enforce the use of SSL.

```
global
        log 127.0.0.1 local0
        log 127.0.0.1 local1 notice
        maxconn 4096
        user haproxy
        group haproxy
        daemon

defaults
        log global
        mode http
        option httplog
        option dontlognull
        option forwardfor
        option http-server-close
        stats enable
        stats auth admin:Password!
        stats uri /haproxyStats

frontend http-in
        bind *:80

        # Define hosts
        acl host_website_hdr(host) -i domain.com 
        acl host_website_hdr(host) -i c.domain.com
        acl host_website_hdr(host) -i s.domain.com
        acl host_website_hdr(host) -i i.domain.com 
        acl host_website_hdr(host) -i e.domain.com

        ## figure out which one to use
        use_backend website if host_website
        use_backend website if host_website
        use_backend website if host_website
        use_backend website if host_website
        use_backend website if host_website

backend website
        balance leastconn
        option httpclose
        option forwardfor
        cookie JSESSIONID prefix
        server node1 10.5.0.10 cookie A check
        server node2 10.5.0.11 cookie A check
        server node3 10.5.0.12 cookie A check
        server node4 10.5.0.13 cookie A check
        server node5 10.5.0.14 cookie A check
```

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 22, 2018, 5:36pm UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/2 "2018-10-22T17:36:33Z")

</div>

Haproxy does not redirect anything in this configuration. Likely your backend server are redirecting. Why that is, is a question that needs to be looked at from the application perspective. Nothing fancy that haproxy does here.

The configuration you posted doesn’t make a lot of sense though, are you sure that’s what you are really using? You don’t need multiple use\_backend that are exactly the same. Once suffices. Also since you don’t have multiple backends, default\_backend probably suffices.

All the SSL questions can be answered when you explain how you would like to set that up. Are the backend servers terminating SSL, or haproxy? Where are the certificates installed?

---

<div class="post-metadata">

**Author:** ![PunkIsDaFunk](https://avatars.discourse-cdn.com/v4/letter/p/77aa72/32.png) [@PunkIsDaFunk](https://discourse.haproxy.org/u/PunkIsDaFunk)\
**Post date:** [October 22, 2018, 10:17pm UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/3 "2018-10-22T22:17:07Z")

</div>

I would prefer that SSL be terminated by HAProxy. (For testing I’m using Lets Encrypt)  
The configuration I have posted is just an example. It’s not something I’m using in a production (or testing) environment.

Essentially, I have 3 servers configured in a network, each has two interfaces:  
server1 10.5.0.10, 10.5.0.11  
server2 10.5.0.12, 10.5.0.13  
server3 10.5.0.14, 10.5.0.15

All of these servers and HAProxy will only serving [domain.com](http://domain.com). Subdomains are also housed on the same servers (10.5.0.10 - 15), but with my previous configuration (this is my second attempt) only displayed the main website ([domain.com](http://domain.com)) for every subdomain. For example, [images.domain.com](http://images.domain.com) is replicated by the servers and should also be handled by HAProxy. But [images.domain.com](http://images.domain.com), displayed the document root for [domain.com](http://domain.com), and not [images.domain.com](http://images.domain.com).

I am new to HAProxy, if there is a configuration that would fit what I am trying to accomplish better than what I posted, please let me know. Configuration examples would be a great resource if you have any. If that makes more sense. Which I hope it does.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 23, 2018, 10:01am UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/4 "2018-10-23T10:01:23Z")

</div>

Remove `option http-server-close` from the defaults and `option httpclose` from the backend. They just disable keep-alive which makes no sense, unless you had a reason to put them there.

SSL configuration in haproxy is fairly straightforward, checkout `examples/ssl.cfg` and the [Mozilla SSL Configuration Generator](https://mozilla.github.io/server-side-tls/ssl-config-generator/?server=haproxy-1.8.0&openssl=1.0.2&hsts=no&profile=modern) for suggestions about how to do it securely.

Just avoid redirecting to SSL from the backend applications (do it in haproxy instead using [redirect scheme](https://cbonte.github.io/haproxy-dconv/1.8/configuration.html#4.2-redirect%20scheme)), otherwise you backend start redirecting to HTTPS endlessly because they don’t know that haproxy actually terminates SSL (you’d have to set a HTTP header like X-Forwarded-Proto on haproxy, and make the application understand it).

If you want cookie persistence (do you?), you need to set each server to a different cookie value, otherwise it makes no sense. In your specific case you could set the same cookie for the other NIC of the same server, that should be fine.

```auto
        server server1-nic1 10.5.0.10 cookie A check
        server server1-nic2 10.5.0.11 cookie A check
        server server2-nic1 10.5.0.12 cookie B check
        server server2-nic2 10.5.0.13 cookie B check
        server server3-nic1 10.5.0.14 cookie C check
        server server3-nic2 10.5.0.15 cookie C check

```

> [@PunkIsDaFunk](#):
>
> For example, [images.domain.com](http://images.domain.com) is replicated by the servers and should also be handled by HAProxy. But [images.domain.com](http://images.domain.com), displayed the document root for [domain.com](http://domain.com), and not [images.domain.com](http://images.domain.com).

That’s your backend server’s domain, haproxy does not know anything about this. You need to look there for fixes. Also, actually test your backend servers directly.

---

<div class="post-metadata">

**Author:** ![PunkIsDaFunk](https://avatars.discourse-cdn.com/v4/letter/p/77aa72/32.png) [@PunkIsDaFunk](https://discourse.haproxy.org/u/PunkIsDaFunk)\
**Post date:** [October 23, 2018, 10:43pm UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/5 "2018-10-23T22:43:03Z")

</div>

> [@lukastribus](#):
>
> That’s your backend server’s domain, haproxy does not know anything about this. You need to look there for fixes. Also, actually test your backend servers directly.

I’m unsure what you mean? There is no way using the domain the browser requests that I can pass the host header of [images.domain.com](http://images.domain.com) on to the server from HAProxy?

The virtual hosts for each subdomain already exist in apache, and point to the correct document root, and the bind server that handles DNS is pointing to the public IP address of the HAProxy server. So the servers are already setup to serve the pages based on the domain names that are requested. HAProxy is only sending the root domain though (or at least I suspect) which is why it’s only displaying the root website, and not the sub-domains.

Correct me if I’m wrong. Which I may be, since I am new to HAProxy.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 24, 2018, 9:27am UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/6 "2018-10-24T09:27:17Z")

</div>

It’s very simple: your browser sets the Host header to `images.domain.com`. Haproxy passes the requests as-is to the backend server, which, if configured correctly, based on the Host header which is set to `images.domain.com`, serves the correct root.

> [@PunkIsDaFunk](#):
>
> HAProxy is only sending the root domain though (or at least I suspect)

No, haproxy won’t touch the Host header send by the browser. Unless you configure haproxy to overwrite the Host header, but that’s not what you configured.

Again test your backend servers directly, without going through haproxy.

---

<div class="post-metadata">

**Author:** ![mdsahil](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mdsahil](https://discourse.haproxy.org/u/mdsahil)\
**Post date:** [March 20, 2019, 7:06am UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/7 "2019-03-20T07:06:46Z")

</div>

In haproxy configuration, acl sub domain is above in main domain. while trying to login the subdomain URL to went to main domain. Please give us solution.  
**haproxy version: 1.6.14**

acl xxx hdr\_end(host) -i xxx.domain.in  
acl xxxmain hdr\_end(host) -i xxxmain.domain.in

use\_backend xxxmain if xxxmain  
use\_backend xxx if xxx

backend xxx  
redirect scheme https if !{ ssl\_fc }  
rspadd X-Frame-Options:\ SAMEORIGIN  
option forwardfor  
balance roundrobin  
cookie SERVERID insert indirect nocache  
server xxx 1.1.1.1:xxxx check ssl verify none

backend xxxmain  
redirect scheme https if !{ ssl\_fc }  
rspadd X-Frame-Options:\ SAMEORIGIN  
option forwardfor  
balance roundrobin  
cookie SERVERID insert indirect nocache  
server xxxmain 1.1.1.1:xxxx check ssl verify none

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [March 25, 2019, 10:35am UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/8 "2019-03-25T10:35:38Z")

</div>

Please open your own thread and don’t hijack others.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [March 25, 2019, 10:35am UTC](https://discourse.haproxy.org/t/haproxy-single-domain-name-multiple-subdomains-with-ssl/3117/9 "2019-03-25T10:35:54Z")

</div>


