Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HAProxy applying same cert to all domains

    Scheduled Pinned Locked Moved Cache/Proxy
    4 Posts 2 Posters 644 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      colinstu
      last edited by

      First asked over on the HAProxy side https://discourse.haproxy.org/t/haproxy-not-routing-to-backend-if-different-domain-is-used/8904
      Sounds like it's possible but I'm not sure how to replicate the requested/required config within the HAProxy UI on PFSense, messed around a bunch and still not getting there.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @colinstu
        last edited by

        @colinstu
        It's not really clear to me, what's your problem.
        From your topic it seems you was not able to add multiple SSL cert to a frontend. This can be easily done in an SSL offloading frontend at "Additional certificates".

        Your post in the HAproxy forum lead me to suspect you want to forward different domains from one frontend to different backend servers.
        This can be achieved with an "host matches" ACL in an http frontend.

        Maybe you can give some more details on your issue.

        C 1 Reply Last reply Reply Quote 1
        • C
          colinstu @viragomann
          last edited by

          @viragomann
          Ok, so I setup the additional certificate, and I checked on the box for "Add ACL for certificate CommonName". Now when I hit the url, the correct cert is being served up, but I'm still getting a 503 error.

          I have the host matches ACL entries setup within the frontend already.

          C 1 Reply Last reply Reply Quote 0
          • C
            colinstu @colinstu
            last edited by

            @colinstu Edit: Huh, after also checking on "Add ACL for certificate Subject Alternative Names." for the alt cert, it now works!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.