# Apache Reverse Proxy

**URL:** https://community.letsencrypt.org/t/apache-reverse-proxy/30074
**Category:** Server
**Created:** [March 17, 2017, 11:49am UTC](https://community.letsencrypt.org/t/apache-reverse-proxy/30074 "2017-03-17T11:49:47Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![barbarukko](https://avatars.discourse-cdn.com/v4/letter/b/dfb087/32.png) [@barbarukko](https://community.letsencrypt.org/u/barbarukko)
#### Post date: [March 17, 2017, 11:49am UTC](https://community.letsencrypt.org/t/apache-reverse-proxy/30074/1 "2017-03-17T11:49:47Z")

</div>

Hi,  
I have an apache proxy that map some services.  
Some are hosted on the same machine under tomcat / https, others are on other machines. I would like to create a new server to host only apache and use as reverse proxy for these services. I would like to use a new clean VM with Apache and “letsencrypt / certbot” to certify services. What is best way to proceed? Can I install on this machine certbot apache and use it to certify all services mapped? As usual routes in this case the verification? Thanks in advance .

my actual apache conf.

```
<IfModule mod_ssl.c>
<VirtualHost *:443>
        ProxyRequests off
        ProxyPreserveHost on
        SSLProxyEngine on

...

        ServerName XYZ

        <Proxy balancer://xyz>
                # WebHead1
                BalancerMember https://AAA.BBB.CCC.DDD:8443
               

                # Security "technically we aren't blocking
                # anyone but this the place to make those
                # chages
                Order Deny,Allow
                Deny from none
                Allow from all

                # Load Balancer Settings
                # We will be configuring a simple Round
                # Robin style load balancer. This means
                # that all webheads take an equal share of
                # of the load.
                ProxySet lbmethod=byrequests

        </Proxy>
... etc
```

---

<div class="post-metadata">

### Author: ![jmorahan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jmorahan/32/1873_2.png) [@jmorahan](https://community.letsencrypt.org/u/jmorahan)
#### Post date: [March 17, 2017, 5:35pm UTC](https://community.letsencrypt.org/t/apache-reverse-proxy/30074/2 "2017-03-17T17:35:36Z")

</div>

I’ve used certbot with mod\_proxy before and the apache plugin seems to handle it just fine, as long as you have your `VirtualHost`s split up into separate files as it expects. I was using `ProxyPass` rather than `<Proxy>`, but I doubt that would make a difference.

Note that the resulting certificates will be installed on the proxy machine to protect the connection between an end-user’s browser and the proxy - they won’t secure the connection from the proxy to the backends. For that it’s probably simpler to [whitelist](https://httpd.apache.org/docs/2.4/mod/mod_ssl.html#sslproxycacertificatefile) some self-signed certs.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [April 16, 2017, 5:35pm UTC](https://community.letsencrypt.org/t/apache-reverse-proxy/30074/3 "2017-04-16T17:35:36Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
