# Need help with HAPROXY https when apps share the SSL cert

**URL:** <https://discourse.haproxy.org/t/need-help-with-haproxy-https-when-apps-share-the-ssl-cert/8959>\
**Category:** Help!\
**Created:** [August 23, 2023, 9:42pm UTC](https://discourse.haproxy.org/t/need-help-with-haproxy-https-when-apps-share-the-ssl-cert/8959 "2023-08-23T21:42:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunnyD](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@sunnyD](https://discourse.haproxy.org/u/sunnyD)\
**Post date:** [August 23, 2023, 9:42pm UTC](https://discourse.haproxy.org/t/need-help-with-haproxy-https-when-apps-share-the-ssl-cert/8959/1 "2023-08-23T21:42:01Z")

</div>

Here is my setup -

frontend HTTPS  
bind \*:443  
mode tcp  
option tcplog  
tcp-request inspect-delay 5s  
tcp-request content accept if { req\_ssl\_hello\_type 1 }

acl HTTPS1 req.ssl\_sni -i [app1.domain1.com](http://app1.domain1.com)  
acl HTTPS2 req.ssl\_sni -i [app2.domain1.com](http://app2.domain1.com)

use\_backend server1 if HTTPS1  
use\_backend server2 if HTTPS2

backend server1  
mode tcp  
option tcplog  
server appserver1 x1.x1.x1.x1:443 check

backend server2  
mode tcp  
option tcplog  
server appserver2 x2.x2.x2.x2:443 check

my problem is that both [app1.domain1.com](http://app1.domain1.com) and [app2.domain1.com](http://app2.domain1.com) share the same SSL cert and it appears that SNI is only triggered once per SSL session so when I open two tabs in the browser, one with [app1.domain1.com](http://app1.domain1.com) and another with [app2.domain1.com](http://app2.domain1.com), I get the same application served up in both tabs.

I dont think there any frontend or backend caching issue. I have attempted using ssl\_fc\_sni instead but that does not work - I get insecure website from the browser and no access to the app. Any way I can get by without using SNI?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [August 24, 2023, 10:21pm UTC](https://discourse.haproxy.org/t/need-help-with-haproxy-https-when-apps-share-the-ssl-cert/8959/2 "2023-08-24T22:21:23Z")

</div>

You need to use different non overlapping certificates.

A wilcard certificate or a certificate containing both hostnames as SAN will lead to this exact issue…

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [August 25, 2023, 6:39am UTC](https://discourse.haproxy.org/t/need-help-with-haproxy-https-when-apps-share-the-ssl-cert/8959/3 "2023-08-25T06:39:11Z")

</div>

An alternative would be to detect the SNI and hostname match in the backend servers and return a `421 Misdirected Request` response error:

[https://www.rfc-editor.org/rfc/rfc7540#section-9.1.2](https://www.rfc-editor.org/rfc/rfc7540#section-9.1.2)
