# SSL passthru not working

**URL:** <https://discourse.haproxy.org/t/ssl-passthru-not-working/6000>\
**Category:** Help!\
**Created:** [December 7, 2020, 10:26am UTC](https://discourse.haproxy.org/t/ssl-passthru-not-working/6000 "2020-12-07T10:26:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tridevk](https://avatars.discourse-cdn.com/v4/letter/t/db5fbb/32.png) [@tridevk](https://discourse.haproxy.org/u/tridevk)\
**Post date:** [December 7, 2020, 10:26am UTC](https://discourse.haproxy.org/t/ssl-passthru-not-working/6000/1 "2020-12-07T10:26:48Z")

</div>

Hi ,

I would like to have ssl -pass thru working for my env.  
from my random read on internet and this side, i understand that i need to use “mode tcp” for ssl-passtru to work. on the fronend, i do lot of filtering by using ACLs , which mostly works with http mode, and i don’t want to lose this flexibility. I read from thread \<([TCP with ACL possible?](https://discourse.haproxy.org/t/tcp-with-acl-possible/283))\> that it is possible to use http mode in front end and tcp mode in backend.

But with that i am getting error as:-  
http frontend ‘web\_gateway’ (/usr/local/etc/haproxy/haproxy.cfg:48) tries to use incompatible tcp backend ‘otntomcat’ (/usr/local/etc/haproxy/haproxy.cfg:166)

Can you please let me know how it (ssl-passthru) can be done without losing the http mode flexibility?

Thanks a lot.

# The haproxy.cfg (shortened one…) is as below.

global  
log stdout format raw local0 debug  
tune.ssl.default-dh-param 2048  
user otn  
group otn  
master-worker

defaults  
mode http  
log global  
option http-server-close  
option httplog  
option dontlognull  
option redispatch  
option forwardfor  
retries 3  
backlog 4096  
timeout client 200s  
timeout client-fin 20s  
timeout connect 5s  
timeout server 100s  
timeout tunnel 15m  
timeout http-keep-alive 30s  
timeout http-request 10s  
timeout queue 5s  
timeout tarpit 60s  
maxconn 10000   
default-server inter 3s rise 2 fall 3 init-addr last,libc,none

frontend default\_ports  
bind \*:80 user otn group otn  
option httplog  
http-request add-header X-Forwarded-Proto https  
http-request redirect location https://"$ipv4addr":"$port"/cas/login

frontend default\_ports\_443  
bind \*:443 user otn group otn ssl crt /usr/local/etc/haproxy/cert.crt  
option tcplog  
acl fault\_path path\_beg -i /FaultManagement  
use\_backend nspos\_serv1 if fault\_path  
default\_backend nspos\_serv

frontend web\_gateway  
bind \*:"$port" ssl crt /usr/local/etc/haproxy/cert.crt  
http-request add-header X-Forwarded-Proto https  
http-request set-query %[query,regsub(:"$port",g)]  
http-request set-uri %[url,regsub(otntomcat,"$ipv4addr",g)]  
redirect scheme https if !{ ssl\_fc }  
acl otntomcat\_path path\_beg -i /oms1350  
acl dojoroot\_path path\_beg -i /dojoroot  
acl p1 path\_beg -i /jointroot  
acl p2 path\_beg -i /jquery  
acl p3 path\_beg -i /lodash  
acl p4 path\_beg -i /openlayersroot  
acl p5 path\_beg -i /search  
acl p6 path\_beg -i /svgutilsroot  
acl p7 path\_beg -i /d3root  
acl p8 path\_beg -i /backbone  
acl p9 path\_beg -i /Cpb  
use\_backend otntomcat if otntomcat\_path || dojoroot\_path || p1 || p2 || p3 || p4 || p5 || p6 || p7 || p8 || p9  
acl cas\_path path\_beg -i /cas  
acl session\_path path\_beg -i /session-manager  
use\_backend nspos\_serv if cas\_path || session\_path  
acl fault\_path path\_beg -i /FaultManagement  
use\_backend nspos\_serv1 if fault\_path  
acl int\_path path\_beg -i /internal  
use\_backend nspos\_serv if int\_path  
acl ntsm\_path path\_beg -i /ntsm  
use\_backend ntsm\_serv if ntsm\_path  
acl systemmonitor\_path path\_beg -i /systemmonitor  
use\_backend systemmonitor\_serv if systemmonitor\_path  
acl wso\_path path\_beg -i /wso  
use\_backend wso\_serv if wso\_path  
acl motn\_path path\_beg -i /onc  
use\_backend motn\_serv if motn\_path  
acl nrct\_tapi\_path path\_beg -i /tapi  
use\_backend nrct\_tapi\_serv if nrct\_tapi\_path  
default\_backend nspos\_serv

resolvers docker\_nfmt-net  
nameserver dns1 127.0.0.11:53

backend otntomcat  
mode http  
balance roundrobin  
log stdout local0 debug  
server serv01 otntomcat:8443 resolvers docker\_nfmt-net check ssl verify none  
http-response replace-header Location (._)(\botntomcat\b)(._)$ \1"ipv4addr"\3 http-response replace-header Location (.\*)(\b80\b)(.\*) \1"port"\3 http-response replace-header Location (.\*)(\b443\b)(.\*) \1"port"\3 http-response replace-header Location (.\*)(\b8544\b)(.\*) \1"port"\3 http-response replace-header Location (.\*)(\b8545\b)(.\*) \1"port"\3 http-response replace-header Location (.\*)(\b8443\b)(.\*) \1"$port"\3  
http-response replace-header Location (._)(\b/oms1350/pages/otn\b)(._) \1:"$port"/oms1350/pages/otn\3  
http-response replace-header Location (._)(\b/oms1350/login/cas\b)(._) \1:"$port"/oms1350/login/cas\3  
http-request add-header X-Forwarded-Proto https if { ssl\_fc }

listen stats  
bind \*:1974  
stats enable  
stats uri /

---

<div class="post-metadata">

**Author:** ![tridevk](https://avatars.discourse-cdn.com/v4/letter/t/db5fbb/32.png) [@tridevk](https://discourse.haproxy.org/u/tridevk)\
**Post date:** [December 8, 2020, 12:17pm UTC](https://discourse.haproxy.org/t/ssl-passthru-not-working/6000/2 "2020-12-08T12:17:49Z")

</div>

Hi @lukastribus , greetings. Can i request your attention on this issue? would like to know if it is possible to have mix mode of http in the front end and tcp in backend and still achieve ssl -passthru?  
thanks  
Tridev

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [December 8, 2020, 2:19pm UTC](https://discourse.haproxy.org/t/ssl-passthru-not-working/6000/3 "2020-12-08T14:19:14Z")

</div>

No, this is absolutely not possible.

The point of SSL is that the content is encrypted. You will never be able to access unencrypted content without decrypting it, and SSL passthrough means that the content will not be decrypted (you’d need the SSL certificate and private key for that).

---

<div class="post-metadata">

**Author:** ![tridevk](https://avatars.discourse-cdn.com/v4/letter/t/db5fbb/32.png) [@tridevk](https://discourse.haproxy.org/u/tridevk)\
**Post date:** [December 9, 2020, 1:23pm UTC](https://discourse.haproxy.org/t/ssl-passthru-not-working/6000/4 "2020-12-09T13:23:10Z")

</div>

Hi @lukastribus, Thank you for your kind response.

It looks like ssl passthu is not possible without a tcp mode. correct?

If you see the server line, i am using “verify none”, that means certificate validation is ignored at HAProxy.  
is it possible to initiate the ssl encyption?  
“server serv01 otntomcat:8443 resolvers docker\_nfmt-net check ssl verify none”  
I am just using the haproxy for reverse proxying. Kindly let me know, if there is any other way to have this configured.  
Thanks  
Tridev

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [December 10, 2020, 5:57pm UTC](https://discourse.haproxy.org/t/ssl-passthru-not-working/6000/5 "2020-12-10T17:57:32Z")

</div>

Correct, SSL passthrough means that you are not decrypting traffic, so you cannot access HTTP. This also implies that you need mode tcp, that is correct.

Do you even need SSL passthrough? It looks like what you are actually trying to do is everything BUT SSL passthrough.

Can you tell me why you dediceded to do SSL passthrough as opposed to SSL termination?

Reminder: SSL passthrough means that you DO NOT have a SSL certificate configured in haproxy, and you never use the `ssl` keyword.

This is SSL passthrough (no `ssl` keyword, no `crt` keyword, no certificate):

```
defaults
 mode tcp
frontend tcp443
 bind :443
 default_backend backend443
backend backend443
 server s1 192.168.1.5:443

```

This is SSL termination (actually `ssl`, `crt` keywords pointing to a certificate):

```
defaults
 mode http
frontend http443
 bind :443 ssl crt /path/to/certificate
 default_backend backend443
backend backend443
 server s1 192.168.1.5:443 ssl verify none
```
