# SSL Termination: Multiple Domains Sharing Same IP and Port

**URL:** <https://discourse.haproxy.org/t/ssl-termination-multiple-domains-sharing-same-ip-and-port/7268>\
**Category:** Help!\
**Created:** [January 5, 2022, 10:18am UTC](https://discourse.haproxy.org/t/ssl-termination-multiple-domains-sharing-same-ip-and-port/7268 "2022-01-05T10:18:31Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [January 5, 2022, 2:41pm UTC](https://discourse.haproxy.org/t/ssl-termination-multiple-domains-sharing-same-ip-and-port/7268/2 "2022-01-05T14:41:18Z")

</div>

This configuration does not make sense to me, let’s clarify what your goals are first.

> [@msm](#):
>
> Trying to compose a config for:
> 
> - SSL Termination of many domains/sub-domains
> - Multiple domains/subdomains on shared IP and Ports, with support for different cert per address
> - HTTP mode (for cookie stickiness, etc.)

You do not appear to have _any_ domains where you need to pass through SSL transparently, without SSL termination.

All the SSL termination should happen on haproxy, correct? There are no (real) backends that expect traffic on port 443?

Why all those duplicates backends?

Unless your requirements are way more complicated, just configure both certificates on the bind line:

```
frontend fe1
  bind *:80
  bind *:443 ssl crt /etc/haproxy/ssl/2.pem crt /etc/haproxy/ssl/1.pem force-tlsv12 force-tlsv12
  default_backend be1

backend be1
  balance roundrobin
  server 1 192.168.20.101:80 check
  server 2 192.168.20.102:80 check

```

---

_[View the full topic](https://discourse.haproxy.org/t/ssl-termination-multiple-domains-sharing-same-ip-and-port/7268)._
