# Problem with http\_auth HAproxy 2.0

**URL:** <https://discourse.haproxy.org/t/problem-with-http-auth-haproxy-2-0/7276>\
**Category:** Help!\
**Created:** [January 9, 2022, 8:27pm UTC](https://discourse.haproxy.org/t/problem-with-http-auth-haproxy-2-0/7276 "2022-01-09T20:27:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![GhostTalker](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/ghosttalker/32/1610_2.png) [@GhostTalker](https://discourse.haproxy.org/u/GhostTalker)\
**Post date:** [January 9, 2022, 8:27pm UTC](https://discourse.haproxy.org/t/problem-with-http-auth-haproxy-2-0/7276/1 "2022-01-09T20:27:15Z")

</div>

Hey,  
i have a problem with basic auth at my haproxy server.  
i followed several todos but none of them are working.

I created a userlist:

userlist trusted\_users  
user user1 insecure-password password1  
user user2 insecure-password password2

and i tried the following in the frontend:

http-request auth unless { http\_auth(trusted\_users) }

or that:

acl auth\_ok http\_auth(trusted\_users)  
http-request auth unless auth\_ok

On both variants i got a HTTP-401 error.  
Any hint why this is not working?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [January 10, 2022, 3:09pm UTC](https://discourse.haproxy.org/t/problem-with-http-auth-haproxy-2-0/7276/2 "2022-01-10T15:09:19Z")

</div>

> [@GhostTalker](#):
>
> HTTP-401 error.

Thats correct behavior: the browser requests a ressource, the server emits a `401 Unauthorized` response so that the browser knows HTTP authentication is required, it will then ask the user for username and password and resend the HTTP requests with this data.

---

<div class="post-metadata">

**Author:** ![GhostTalker](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/ghosttalker/32/1610_2.png) [@GhostTalker](https://discourse.haproxy.org/u/GhostTalker)\
**Post date:** [January 10, 2022, 3:45pm UTC](https://discourse.haproxy.org/t/problem-with-http-auth-haproxy-2-0/7276/3 "2022-01-10T15:45:15Z")

</div>

but i tested the proxy with user and password. So the behavier is not what i am expecting.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [January 11, 2022, 9:07am UTC](https://discourse.haproxy.org/t/problem-with-http-auth-haproxy-2-0/7276/4 "2022-01-11T09:07:49Z")

</div>

And how are you testing exactly and what behavior are you seeing?

Right now the only information you provided is that it is not working and that you get a 401 response.

To help you, you will have to provide more informations, I also suggest you share the full configuration and a full trace of `curl -vv http://username:password@site/`

---

<div class="post-metadata">

**Author:** ![GhostTalker](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/ghosttalker/32/1610_2.png) [@GhostTalker](https://discourse.haproxy.org/u/GhostTalker)\
**Post date:** [January 11, 2022, 9:58am UTC](https://discourse.haproxy.org/t/problem-with-http-auth-haproxy-2-0/7276/5 "2022-01-11T09:58:22Z")

</div>

root@xxxxx:/# curl -vv -x 138.201.134.101:9200 -U user1:password1 [https://google.com](https://google.com)

- Trying 138.201.134.101:9200…
- TCP\_NODELAY set
- Connected to 138.201.134.101 (138.201.134.101) port 9200 (#0)
- allocate connect buffer!
- Establish HTTP proxy tunnel to [google.com:443](http://google.com:443)
- Proxy auth using Basic with user ‘user1’

> CONNECT [google.com:443](http://google.com:443) HTTP/1.1  
> Host: [google.com:443](http://google.com:443)  
> Proxy-Authorization: Basic dXNlcjE6cGFzc3dvcmQx  
> User-Agent: curl/7.68.0  
> Proxy-Connection: Keep-Alive

\< HTTP/1.1 401 Unauthorized  
\< content-length: 112  
\< cache-control: no-cache  
\< content-type: text/html  
\< www-authenticate: Basic realm=“proxy\_in”

- Authentication problem. Ignoring this.  
\< connection: close  
\<
- Received HTTP code 401 from proxy after CONNECT
- CONNECT phase completed!
- Closing connection 0  
curl: (56) Received HTTP code 401 from proxy after CONNECT

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [January 11, 2022, 3:43pm UTC](https://discourse.haproxy.org/t/problem-with-http-auth-haproxy-2-0/7276/6 "2022-01-11T15:43:57Z")

</div>

Haproxy is primarily a reverse proxy, not a forward proxy.

I suggest you use an actual forward proxy instead, likey `tinyproxy`. Bending haproxy to your will for a use-case that is was not designed will result in a mess.
