# Multiple domain with different SSL Certificate

**URL:** <https://discourse.haproxy.org/t/multiple-domain-with-different-ssl-certificate/3714>\
**Category:** Help!\
**Created:** [April 11, 2019, 1:01pm UTC](https://discourse.haproxy.org/t/multiple-domain-with-different-ssl-certificate/3714 "2019-04-11T13:01:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gertbus](https://avatars.discourse-cdn.com/v4/letter/g/a8b319/32.png) [@gertbus](https://discourse.haproxy.org/u/gertbus)\
**Post date:** [April 11, 2019, 1:01pm UTC](https://discourse.haproxy.org/t/multiple-domain-with-different-ssl-certificate/3714/1 "2019-04-11T13:01:22Z")

</div>

Currently we are using for our domain : mylab.macsys.be the following configuration 🙂

defaults  
log global  
option dontlognull # Do not log connections with no requests  
option redispatch # Try another server in case of connection failure  
option contstats # Enable continuous traffic statistics updates  
timeout server 30s  
timeout connect 60s  
timeout client 30s

frontend http\_frontend

bind \*:80  
mode tcp  
default\_backend web\_server\_http

backend web\_server\_http  
mode tcp  
balance roundrobin  
#stick-table type ip size 200k expire 30m  
#stick on src  
#source 0.0.0.0 usesrc clientip #alctl: connect source and transparent connect  
server s1 10.2.0.67:80 check fall 3 rise 2  
server s2 10.2.0.68:80 check fall 3 rise 2  
server s3 10.2.0.69:80 check fall 3 rise 2

frontend https\_frontend

bind \*:443  
mode tcp  
default\_backend web\_server

backend web\_server  
mode tcp  
balance roundrobin  
#stick-table type ip size 200k expire 30m  
#stick on src  
#source 0.0.0.0 usesrc clientip #alctl: connect source and transparent connect  
server s1 10.2.0.67:4431 check fall 3 rise 2  
server s2 10.2.0.68:4431 check fall 3 rise 2  
server s3 10.2.0.69:4431 check fall 3 rise 2

The problem is we want a new domain (www.ipatient.be with specific certificate) active on the same servers. So i guess based on SNI? The mylab.macsys.be:443 domain is running smooth, and we don’t want to disturb our users with problems.

How can we get both www.macsys.be and www.ipatient.be domain working ? Any ideas regarding configuration ?

Listening ports on our IIS Servers :  
macsys.be ==\> port 4431 with macsys.be certificate  
ipatient.be ==\> port 4432 with ipatient.be certificate

Many thanks  
De Busser Gert

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [April 11, 2019, 3:29pm UTC](https://discourse.haproxy.org/t/multiple-domain-with-different-ssl-certificate/3714/2 "2019-04-11T15:29:42Z")

</div>

So you don’t terminate SSL on haproxy (install the SSL certificates on haproxy), but forward it to backend servers which are actually terminating SSL there.

Therefor you need to load-balance based on SNI, but without SSL termination.

Rename the backend web\_server to something that is indicative of what the backend actually is, like macsys\_https. The new backend would then be ipatient\_https.

In that case, to route `ipatient.be` to ipatient\_https, and use the macsys\_https backend otherwise, you’d configure in your HTTPS frontend:

```
frontend https_frontend
 bind *:443
 mode tcp
 tcp-request inspect-delay 5s
 tcp-request content accept if { req_ssl_hello_type 1 }
 use_backend ipatient_https if { req_ssl_sni -i ipatient.be } || { req_ssl_sni -i www.ipatient.be }
 default_backend macsys_https
```

---

<div class="post-metadata">

**Author:** ![gertbus](https://avatars.discourse-cdn.com/v4/letter/g/a8b319/32.png) [@gertbus](https://discourse.haproxy.org/u/gertbus)\
**Post date:** [April 12, 2019, 10:53am UTC](https://discourse.haproxy.org/t/multiple-domain-with-different-ssl-certificate/3714/3 "2019-04-12T10:53:04Z")

</div>

Many thx ! and with the || (or) solution even better than what i found on the web.
