# Ssl\_client\_certificate and ssl\_verify\_client to haproxy

**URL:** <https://discourse.haproxy.org/t/ssl-client-certificate-and-ssl-verify-client-to-haproxy/3328>\
**Category:** Help!\
**Created:** [December 17, 2018, 1:57pm UTC](https://discourse.haproxy.org/t/ssl-client-certificate-and-ssl-verify-client-to-haproxy/3328 "2018-12-17T13:57:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tiagocruz](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/tiagocruz/32/193_2.png) [@tiagocruz](https://discourse.haproxy.org/u/tiagocruz)\
**Post date:** [December 17, 2018, 1:57pm UTC](https://discourse.haproxy.org/t/ssl-client-certificate-and-ssl-verify-client-to-haproxy/3328/1 "2018-12-17T13:57:47Z")

</div>

Hello guys,

I’m having a hard time trying to convert this snipet from nginx to haproxy:

```auto
    ### SSL cert files ###
    ssl on;
    ssl_certificate /keys/xxx.com.pem;
    ssl_certificate_key /keys/xxx.com.key;
    ssl_client_certificate /keys/client_certs.crt;
    ssl_verify_client on;
    ssl_verify_depth 2;

```

The goal is to require client to be authenticated through certificate listed in “client\_certs.crt”.

Coud you please help with the equivalent in haproxy?

Thanks!!!

---

<div class="post-metadata">

**Author:** ![shivharsh](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/shivharsh/32/388_2.png) [@shivharsh](https://discourse.haproxy.org/u/shivharsh)\
**Post date:** [December 19, 2018, 10:39am UTC](https://discourse.haproxy.org/t/ssl-client-certificate-and-ssl-verify-client-to-haproxy/3328/2 "2018-12-19T10:39:16Z")

</div>

Hi,  
In order to verify client certificates in HAProxy, you need to set the “verify” option to “required”. The certificates provided by the client are to be verified using a CA listed in “ca-file”, which is a PEM file containing CA certificates.

> [@tiagocruz](#):
>
> ### SSL cert files ### ssl on; ssl\_certificate /keys/xxx.com.pem; ssl\_certificate\_key /keys/xxx.com.key; ssl\_client\_certificate /keys/client\_certs.crt; ssl\_verify\_client on; ssl\_verify\_depth 2;

For you to implement the nginx snippet in HAProxy, you would need to make below changes in the frontend section of haproxy.cfg:

```
	frontend example_FE
		mode http
		bind *:443 ssl crt /keys/xxx.com.pem ca-file /keys/client_certs.crt verify required
		default-backend example_BE

```

Also, as far as i am aware, haproxy does not support limiting client ssl certificate verification depth. Therefore, ssl\_verify\_depth is not configured in the above haproxy configuration.

Hope this is helpful !

Thanks,  
Shivharsh

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [December 19, 2018, 10:11pm UTC](https://discourse.haproxy.org/t/ssl-client-certificate-and-ssl-verify-client-to-haproxy/3328/3 "2018-12-19T22:11:01Z")

</div>

Regarding the ssl verification depth, haproxy veryfies the entire chain. You can access variables like [ssl\_c\_ca\_err\_depth](https://cbonte.github.io/haproxy-dconv/1.8/configuration.html#7.3.4-ssl_c_ca_err_depth) or [ssl\_c\_ca\_err](https://cbonte.github.io/haproxy-dconv/1.8/configuration.html#7.3.4-ssl_c_ca_err) to understand what error happen on what depth.

You can also choose to ignore certain errors with [ca-ignore-err](https://cbonte.github.io/haproxy-dconv/1.8/configuration.html#5.1-ca-ignore-err).

None of this should be necessary though, as by default haproxy verifies the full chain, which you probably expect.

---

<div class="post-metadata">

**Author:** ![tiagocruz](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/tiagocruz/32/193_2.png) [@tiagocruz](https://discourse.haproxy.org/u/tiagocruz)\
**Post date:** [December 20, 2018, 9:28am UTC](https://discourse.haproxy.org/t/ssl-client-certificate-and-ssl-verify-client-to-haproxy/3328/4 "2018-12-20T09:28:16Z")

</div>

Thanks guys! I’m using:

```auto
    bind :11001 transparent ssl crt bla.crt ca-file bla.crt verify required crl-file client_certs.crt crt-ignore-err all

```

And is working!
