# How to configure HAproxy for a certificate authentication

**URL:** <https://discourse.haproxy.org/t/how-to-configure-haproxy-for-a-certificate-authentication/8017>\
**Category:** Help!\
**Created:** [October 12, 2022, 12:24pm UTC](https://discourse.haproxy.org/t/how-to-configure-haproxy-for-a-certificate-authentication/8017 "2022-10-12T12:24:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jameil](https://avatars.discourse-cdn.com/v4/letter/j/bc8723/32.png) [@jameil](https://discourse.haproxy.org/u/jameil)\
**Post date:** [October 12, 2022, 12:24pm UTC](https://discourse.haproxy.org/t/how-to-configure-haproxy-for-a-certificate-authentication/8017/1 "2022-10-12T12:24:47Z")

</div>

Good Evening,

I want to have a certificate-based authentication configured only on a backend

> test5\_ssl

in such a way that the configuration would not impact other nodes (test\_1\_ssl, test\_2\_ssl, test\_3\_ssl, test\_4\_ssl). My question is how to do it?

P.S.

my HAProxy version is 1.5.18

I have a following configuration

> frontend primordial\_ssl  
> log 127.0.0.1:514 local0 notice  
> mode http  
> —\>\>\> LINE of INTEREST bind \*:443 ssl crt /etc/ssl/server.pem ca-file /etc/haproxy/ca.crt verify required  
> http-request set-header X-SSL-Client %{+Q}[ssl\_c\_der,base64]  
> acl test\_1 hdr\_dom(host) -i -f /etc/haproxy/test1  
> acl test\_2 hdr\_dom(host) -i -f /etc/haproxy/test2  
> acl test\_3 hdr\_dom(host) -i -f /etc/haproxy/test3  
> use\_backend test\_1\_ssl if test\_1  
> use\_backend test\_2\_ssl if test\_2  
> use\_backend test\_3\_ssl if test\_3  
> default\_backend test4
> 
> backend test\_1\_ssl  
> mode http  
> balance roundrobin  
> option forwardfor  
> cookie testcookie prefix nocache  
> option httpchk HEAD / HTTP/1.1.\r\nHost:localhost  
> http-request set-header X-Forwarded-Host %[req.hdr(Host)]  
> http-request set-header X-Forwarded-Port %[dst\_port]  
> http-request set-header X-Forwarded-Proto https  
> redirect scheme https if !{ ssl\_fc }  
> server test1\_s [test.com:18443](http://test.com:18443) cookie 01 id 1011 ssl verify none  
> errorfile 503 /etc/haproxy/maintenance\_pages/testmaintenance1.http
> 
> backend test\_2\_ssl  
> mode http  
> balance roundrobin  
> option forwardfor  
> cookie test2cookie prefix nocache  
> option httpchk HEAD / HTTP/1.1.\r\nHost:localhost  
> http-request set-header X-Forwarded-Host %[req.hdr(Host)]  
> http-request set-header X-Forwarded-Port %[dst\_port]  
> http-request set-header X-Forwarded-Proto https  
> redirect scheme https if !{ ssl\_fc }  
> server test2\_s [test.com:18443](http://test.com:18443) cookie 01 id 11011 ssl verify none  
> errorfile 503 /etc/haproxy/maintenance\_pages/test2.http
> 
> backend test3\_ssl  
> mode http  
> balance roundrobin  
> option forwardfor  
> option httpchk HEAD / HTTP/1.1.\r\nHost:localhost  
> cookie test3cookie insert indirect nocache  
> http-request set-header X-Forwarded-Host %[req.hdr(Host)]  
> http-request set-header X-Forwarded-Port %[dst\_port]  
> http-request set-header X-Forwarded-Proto https  
> redirect scheme https if !{ ssl\_fc }  
> server test3\_s [test.com:8443](http://test.com:8443) cookie 01 id 4011 ssl verify none  
> errorfile 503 /etc/haproxy/maintenance\_pages/testmaintenance1.http
> 
> backend test4\_ssl  
> mode http  
> balance roundrobin  
> option forwardfor  
> option httpchk HEAD / HTTP/1.1.\r\nHost:localhost  
> cookie test4cookie insert indirect nocache  
> http-request set-header X-Forwarded-Host %[req.hdr(Host)]  
> http-request set-header X-Forwarded-Port %[dst\_port]  
> http-request set-header X-Forwarded-Proto https  
> redirect scheme https if !{ ssl\_fc }  
> server test4\_s [test.com:8443](http://test.com:8443) cookie 01 id 4011 ssl verify none  
> errorfile 503 /etc/haproxy/maintenance\_pages/testmaintenance1.http
> 
> #—\>\> HOW to configure this node to accept only certificate based connections  
> #—\>\> without any impact on other nodes?  
> backend test5\_ssl  
> mode http  
> #bind \*:443 ssl crt /etc/ssl/server.pem ca-file /etc/haproxy/ca.crt  
> balance roundrobin  
> http-request set-header X-Forwarded-Host %[req.hdr(Host)]  
> http-request set-header X-Forwarded-Port %[dst\_port]  
> http-request set-header X-Forwarded-Proto http  
> option forwardfor except 127.0.0.0/8  
> cookie test5cookie  
> server test5 [test.com:19090](http://test.com:19090) cookie 01 id 1001 check inter 2000 rise 2 fall 5  
> errorfile 503 /etc/haproxy/maintenance\_pages/testmaintenance1.http

---

<div class="post-metadata">

**Author:** ![Markus](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@Markus](https://discourse.haproxy.org/u/Markus)\
**Post date:** [October 13, 2022, 9:08am UTC](https://discourse.haproxy.org/t/how-to-configure-haproxy-for-a-certificate-authentication/8017/2 "2022-10-13T09:08:36Z")

</div>

have a look at

> **[SSL Client Certificate Management at Application Level - HAProxy Technologies](https://www.haproxy.com/blog/ssl-client-certificate-management-at-application-level/)**
>
> HAProxy can also offload client certificate management from servers with some advanced features. In this blog post, we will show how enable this feature.

i think it ist not possible to have client auth at backend level (this is communicaiton between haproxy and backend server) . you can setup an auth so that haproxy will be required to do auth against backend. but you can’t pass client auth info to backend.

so you can configure your frontend (listener) to do client auth. You can’t pass the client certificate to backend server (i beleieve) but you can send infos as ENV-Vars, so you can send username, mail etc. as ENV var and use it (as trusted vars) on your backend.

i wanted to use it on my stats/admin page. i have a client auth setup for direct access my backend server. it would work on haproxy admin page. but the problem is, i access it via ip-address and not domain name and so the client ssl auth will fail (as no matching domain is found)

markus
