logo
Apache Lounge
Webmasters

 

About Forum Index Downloads Search Register Log in RSS X


Keep Server Online

If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.

or

Bitcoin

A donation makes a contribution towards the costs, the time and effort that's going in this site and building.

Thank You! Steffen

Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
Post new topic   Forum Index -> Apache View previous topic :: View next topic
Reply to topic   Topic: SSL Questions for Proxy Server and Individual Web Servers
Author
sjuanes



Joined: 26 Feb 2014
Posts: 1

PostPosted: Thu 27 Feb '14 2:14    Post subject: SSL Questions for Proxy Server and Individual Web Servers Reply with quote

New to the forum and had some SSL certificate questions. I appologize ahead of time if my wording and term usage is off. So here is some background:

I have a total of 3 web servers:

x1 gateway.domain.com:443 (Using as a proxy to web1 and web2)
x1 web1.domain.com:443
x1 web2.domain.com:443

I was able to have gateway.domain.com play nicely with a wildcard certificate and handshake perfectly with web1 and web2. Now currently, web1 and web2 have their own SSL certificates while gateway has a wildcard cert for *.domain.com. Is it necessary to have certs on all 3 servers or just have the single wildcard cert on gateway.domain.com?

I believe my understanding of how the handshake works is where I am stumbling. Thank you.
Back to top
Anaksunaman



Joined: 19 Dec 2013
Posts: 54

PostPosted: Thu 27 Feb '14 12:10    Post subject: SSL Questions for Proxy Server and Individual Web Server Reply with quote

It seems that you would like HTTPS on both the internal and external networks.

The most likely scenario for this would be then:

A) Proxy - 3 certificates (*.domain.tld to catch anything that is HTTPS but not Server 1 or Server 2, plus the two the server certificates to be referenced in a 443 virtual hosts for each web server.)

B) Server 1 -- Certificate 1

C) Server 2 -- Certificate 2

If you ditch HTTPS internally, you can most likely just use either the wildcard domain certificate, or reference the other certificates for each web server in your 443 virtual hosts.
Back to top


Reply to topic   Topic: SSL Questions for Proxy Server and Individual Web Servers View previous topic :: View next topic
Post new topic   Forum Index -> Apache