# SSL certificates

**URL:** <https://discourse.haproxy.org/t/ssl-certificates/2076>\
**Category:** Help!\
**Created:** [February 5, 2018, 5:43am UTC](https://discourse.haproxy.org/t/ssl-certificates/2076 "2018-02-05T05:43:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![badhonsoam](https://avatars.discourse-cdn.com/v4/letter/b/779978/32.png) [@badhonsoam](https://discourse.haproxy.org/u/badhonsoam)\
**Post date:** [February 5, 2018, 5:43am UTC](https://discourse.haproxy.org/t/ssl-certificates/2076/1 "2018-02-05T05:43:30Z")

</div>

How i use ssl web server in the background  
can anyone give me sample?  
i already done in normal http but how Can i do https please guide me through process

---

<div class="post-metadata">

**Author:** ![shivharsh](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/shivharsh/32/388_2.png) [@shivharsh](https://discourse.haproxy.org/u/shivharsh)\
**Post date:** [February 20, 2018, 3:24am UTC](https://discourse.haproxy.org/t/ssl-certificates/2076/2 "2018-02-20T03:24:48Z")

</div>

Hi,

Yes you can use SSL enabled webservers in the HAProxy backend.  
HAProxy by design is a proxy and threfore maintains 2 different connections:  
1. Connection between the client and the HAProxy.  
2. Connection between the server and the HAProxy.

This design therefore allows HAProxy to use different protocols on each type of connection. Hence, SSL can be used for both of these connections or either of these connections. Depending on the way SSL is used, HAProxy can work in following 4 designs:  
1. **SSL/TLS Pass-through** : In this design, HAProxy doesn’t decipher the traffic. It just opens a TCP tunnel between the client and the server and let them together negotiate and handle the SSL traffic.  
2. **SSL/TLS Termination** : In this design, HAProxy decipher the traffic on the client side and gets connected in the clear (without SSL) to the server side.   
3. **SSL/TLS Bridging** : In this design, HAProxy decipher the traffic on the client side and re-encrypt it on the server side.  
4. **SSL/TLS Encryption** : In this mode, HAProxy get the traffic in clear on the client side and uses TLS to get connected on the server side.

Below are the steps to be performed to handle SSL connection at HAProxy:

1. Place the .pem file of the SSL certificate in a /etc/ssl/certs/

2. Use below lines in the frontend section of HAProxy configuration to use HAProxy in SSL/TLS Termination design.  
**frontend abc**  
mode http  
bind [ha.nec.com:443](http://ha.nec.com:443) ssl crt /etc/ssl/certs/haproxy\_certificate.pem

Use below lines in the frontend and backend section of HAProxy configuration to use HAproxy in SSL Encryption design.  
**frontend abc**  
mode http  
bind [ha.nec.com:80](http://ha.nec.com:80)  
default\_backed xyz  
**backend xyz**  
mode http  
server [wbs1.nec.com](http://wbs1.nec.com) 10.0.4.113:443 check ssl cookie 1

1. Restart haproxy.service after the configurational changes.

Hope this is helpful !
