# Redirecting HTTP to HTTPS

**URL:** <https://discourse.haproxy.org/t/redirecting-http-to-https/2112>\
**Category:** Help!\
**Created:** [February 12, 2018, 12:29am UTC](https://discourse.haproxy.org/t/redirecting-http-to-https/2112 "2018-02-12T00:29:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![satya](https://avatars.discourse-cdn.com/v4/letter/s/8c91f0/32.png) [@satya](https://discourse.haproxy.org/u/satya)\
**Post date:** [February 12, 2018, 12:29am UTC](https://discourse.haproxy.org/t/redirecting-http-to-https/2112/1 "2018-02-12T00:29:18Z")

</div>

Hi,

I am trying to simple route all the HTTP requests made to the server to redirect as HTTPS to external server.

Can you please help with the it?

Code:  
frontend localhost  
bind :80  
option tcplog  
mode tcp  
default\_backend nodes

backend nodes  
mode tcp  
option ssl-hello-chk  
server sv1 10.192.x.x:443

Also I am trying to use curl (below command) and it should redirect to [https://v1/health](https://v1/health) to fetch the data.  
The https url works without any issue, so there is no connectivity issue from the machine. But the localhost url  
doesn’t work.

> curl -X GET [http://localhost/health](http://localhost/health)  
> curl: (52) Empty reply from server

> curl -X GET [https://sv1/health](https://sv1/health)  
> {“status”:“UP”,“diskSpace”:{“status”:“UP”,“total”:1073741824,“free”:913141760,“threshold”:10485760}}

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [February 12, 2018, 8:49pm UTC](https://discourse.haproxy.org/t/redirecting-http-to-https/2112/2 "2018-02-12T20:49:45Z")

</div>

Would you like to redirect (send a redirect message to the client to let him connect _directly_ the https on port 443), then remove the backend and just put this in your port 80 frontend:

`redirect scheme https`

(you don’t even need the `if !{ ssl_fc }` condition, as in a port 80 frontend you already know it’s not encrypted).

Or would you like to “route” the traffic to your secure backend, by stripping SSL from it. Then you need to add the [ssl](https://cbonte.github.io/haproxy-dconv/1.7/configuration.html#5.2-ssl) (and probably [verify none](https://cbonte.github.io/haproxy-dconv/1.7/configuration.html#5.2-verify)) keyword to your server sv1 line (so that SSL is used to connect to it):

`server sv1 10.192.x.x:443 ssl verify none`

---

<div class="post-metadata">

**Author:** ![satya](https://avatars.discourse-cdn.com/v4/letter/s/8c91f0/32.png) [@satya](https://discourse.haproxy.org/u/satya)\
**Post date:** [February 13, 2018, 12:39am UTC](https://discourse.haproxy.org/t/redirecting-http-to-https/2112/3 "2018-02-13T00:39:00Z")

</div>

Basically we have installed HAPROXY in between the client application server and the service-provider server

Client app server can only make http calls, whereas the service-provider server accepts only https calls with certificate for incoming traffic.

So we are planning to use HAProxy to listen to the client on 80 and in the backend convert the call as HTTPS

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [February 13, 2018, 8:01am UTC](https://discourse.haproxy.org/t/redirecting-http-to-https/2112/4 "2018-02-13T08:01:51Z")

</div>

So its not a redirect. From my previous post, use the latter configuration.
