# Stickiness on backend server using X-SSL-Client-CN

**URL:** <https://discourse.haproxy.org/t/stickiness-on-backend-server-using-x-ssl-client-cn/365>\
**Category:** Help!\
**Created:** [June 7, 2016, 10:34am UTC](https://discourse.haproxy.org/t/stickiness-on-backend-server-using-x-ssl-client-cn/365 "2016-06-07T10:34:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![deepagarhaproxy](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@deepagarhaproxy](https://discourse.haproxy.org/u/deepagarhaproxy)\
**Post date:** [June 7, 2016, 10:34am UTC](https://discourse.haproxy.org/t/stickiness-on-backend-server-using-x-ssl-client-cn/365/1 "2016-06-07T10:34:14Z")

</div>

Hello

I am trying to do stickiness on X-SSL-Client-CN but requests still go roundrobin on both backend servers.  
The CN is set properly in SSL connection from client to HAProxy.

Please suggest missing config?

X-SSL-Client-CN = client

backend cdp1  
mode tcp  
balance roundrobin

```
stick-table type string size 204800
stick store-request req.hdr(X-SSL-Client-CN)
stick match req.hdr(X-SSL-Client-CN)

server app1 1.0.0.1:22 check
server app2 1.0.0.2:22 check
timeout server 2h
```

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [June 7, 2016, 12:46pm UTC](https://discourse.haproxy.org/t/stickiness-on-backend-server-using-x-ssl-client-cn/365/2 "2016-06-07T12:46:47Z")

</div>

Who is setting the X-SSL-Client-CN header? The browser/client? That seems strange. You probably want to use the pattern %{+Q}[ssl\_c\_s\_dn(cn)]

---

<div class="post-metadata">

**Author:** ![deepagarhaproxy](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@deepagarhaproxy](https://discourse.haproxy.org/u/deepagarhaproxy)\
**Post date:** [June 7, 2016, 4:41pm UTC](https://discourse.haproxy.org/t/stickiness-on-backend-server-using-x-ssl-client-cn/365/3 "2016-06-07T16:41:01Z")

</div>

This pattern throws the error. Is there anything wrong in this config?

backend cdp1  
mode tcp  
balance roundrobin

```
stick-table type string size 204800
stick store-request %{+Q}[ssl_c_s_dn(cn)]
stick match %{+Q}[ssl_c_s_dn(cn)]

server app1 1.0.0.1:22 check
server app2 1.0.0.2:22 check
timeout server 2h

```

[ALERT] 158/123804 (25481) : parsing [/etc/haproxy/haproxy.cfg:154] : ‘stick’: unknown fetch method ‘%{+Q}[ssl\_c\_s\_dn’  
[ALERT] 158/123804 (25481) : parsing [/etc/haproxy/haproxy.cfg:155] : ‘stick’: unknown fetch method ‘%{+Q}[ssl\_c\_s\_dn’  
[ALERT] 158/123804 (25481) : Error(s) found in configuration file : /etc/haproxy/haproxy.cfg

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [June 7, 2016, 4:50pm UTC](https://discourse.haproxy.org/t/stickiness-on-backend-server-using-x-ssl-client-cn/365/4 "2016-06-07T16:50:04Z")

</div>

Try just ssl\_c\_s\_dn(cn)

---

<div class="post-metadata">

**Author:** ![deepagarhaproxy](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@deepagarhaproxy](https://discourse.haproxy.org/u/deepagarhaproxy)\
**Post date:** [June 7, 2016, 5:31pm UTC](https://discourse.haproxy.org/t/stickiness-on-backend-server-using-x-ssl-client-cn/365/5 "2016-06-07T17:31:45Z")

</div>

I got it working. stick match should come before stick store.

Thanks,

# Client request One : CN=client1

$ echo “show table cdp1” | sudo socat /var/run/haproxy.sock stdio  
table: cdp1, type: string, size:204800, used:0

$ echo “show table cdp1” | sudo socat /var/run/haproxy.sock stdio  
table: cdp1, type: string, size:204800, used:1  
0xab4f24: key=client1 use=0 exp=0 server\_id=1

# Client request Two: CN=client1

$ echo “show table cdp1” | sudo socat /var/run/haproxy.sock stdio  
table: cdp1, type: string, size:204800, used:1  
0xab4f24: key=client1 use=0 exp=0 server\_id=1

backend cdp1  
mode tcp  
balance roundrobin

```
stick-table type string size 204800
stick match ssl_c_s_dn(cn)
stick store-request ssl_c_s_dn(cn)

server app1 1.0.0.1:22 check
server app2 1.0.0.2:22 check
timeout server 2h
```
