# How to configure TLS client certificate authentication only for specific paths?

**URL:** <https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346>\
**Category:** Help!\
**Created:** [December 21, 2018, 1:21pm UTC](https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346 "2018-12-21T13:21:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![marq](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/marq/32/712_2.png) [@marq](https://discourse.haproxy.org/u/marq)\
**Post date:** [December 21, 2018, 1:21pm UTC](https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346/1 "2018-12-21T13:21:48Z")

</div>

The following blog post describes how to configure TLS client certificate authentication with HA Proxy: [https://loadbalancer.org/blog/client-certificate-authentication-with-haproxy/](https://loadbalancer.org/blog/client-certificate-authentication-with-haproxy/)

This question describes how to enable it based on domain name: [How to set ssl verify client for specific domain name](https://discourse.haproxy.org/t/how-to-set-ssl-verify-client-for-specific-domain-name/1489)

However, I would like to enable it based on url path.  
Example:  
Required for:  
[https://my-domain.com/path1](https://my-domain.com/path1)  
But disabled for:  
[https://my-domain.com/path2](https://my-domain.com/path2)

Note: I am terminating the TLS connection at HA Proxy. So the information should be accessible to HA Proxy.  
Before I started using HA Proxy I could do this easily in Apache, by putting the [SSLVerifyClient](https://httpd.apache.org/docs/2.4/mod/mod_ssl.html#sslverifyclient) inside a [Location](https://httpd.apache.org/docs/2.4/mod/core.html#location) block.

Is this possible with HA Proxy? If so, how can it be done?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [December 21, 2018, 1:44pm UTC](https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346/2 "2018-12-21T13:44:30Z")

</div>

No, this is not possible with haproxy.

I know that it is possible with Apache, it’s achieved by triggering a TLS renegotiation. With TLSv1.3 this changes completely, [as renegotiation is no longer supported](https://wiki.openssl.org/index.php/TLS1.3#Renegotiation). Instead TLSv1.3 uses CertificateRequest messages to request the client certificate after the handshake.

Neither is support in haproxy and I doubt Apache supports it in TLSv1.3.

---

<div class="post-metadata">

**Author:** ![marq](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/marq/32/712_2.png) [@marq](https://discourse.haproxy.org/u/marq)\
**Post date:** [December 21, 2018, 1:54pm UTC](https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346/3 "2018-12-21T13:54:34Z")

</div>

Do you know whether adding support for the new TLSv1.3 way for doing this is planned?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [December 21, 2018, 2:05pm UTC](https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346/4 "2018-12-21T14:05:18Z")

</div>

I don’t think so, no.

You may want to ask on the mailing list, but I doubt it.

---

<div class="post-metadata">

**Author:** ![marq](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/marq/32/712_2.png) [@marq](https://discourse.haproxy.org/u/marq)\
**Post date:** [December 21, 2018, 2:13pm UTC](https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346/5 "2018-12-21T14:13:26Z")

</div>

Do you have any idea of how hard it would be to add it?  
Depending on how much work it is, we might consider implementing it ourselves, and adding a pull request for it.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [December 21, 2018, 2:19pm UTC](https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346/6 "2018-12-21T14:19:35Z")

</div>

I’m not sure. I guess it could be quite complex, given how the connection, mux and transaction layer have been separated now, especially with HTTP/2.

Definitely discuss this on the mailing list _before_ investing any actual development time on your end. The developers on the mailing list will have a better idea of how feasible it is.

---

<div class="post-metadata">

**Author:** ![marq](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/marq/32/712_2.png) [@marq](https://discourse.haproxy.org/u/marq)\
**Post date:** [December 21, 2018, 3:12pm UTC](https://discourse.haproxy.org/t/how-to-configure-tls-client-certificate-authentication-only-for-specific-paths/3346/7 "2018-12-21T15:12:19Z")

</div>

Ok, will contact the mailing list if we decide we want to pursue this further.  
Thanks for your help and quick responses!
