# How to configure apahce as reverse proxy for tomcat7?

**URL:** <https://community.letsencrypt.org/t/how-to-configure-apahce-as-reverse-proxy-for-tomcat7/54674>\
**Category:** Help\
**Created:** [March 3, 2018, 12:02am UTC](https://community.letsencrypt.org/t/how-to-configure-apahce-as-reverse-proxy-for-tomcat7/54674 "2018-03-03T00:02:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![am0awad](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/am0awad/32/20811_2.png) [@am0awad](https://community.letsencrypt.org/u/am0awad)\
**Post date:** [March 3, 2018, 12:02am UTC](https://community.letsencrypt.org/t/how-to-configure-apahce-as-reverse-proxy-for-tomcat7/54674/1 "2018-03-03T00:02:34Z")

</div>

Hello All, I have configured my tomcat7 to use SSL successfully on port 8443.  
Now I want to accept for 443 port only I am using apache2 in front of it.  
I added virtual host and this is the content:

```
ServerName example.com
ServerAlias *.example.com
ProxyPreserveHost on
ProxyRequests off

      <Proxy *>
              Order deny,allow
              Allow from all
       </Proxy>

SSLEngine on
SSLProxyEngine on
SSLVerifyClient None
SSLCertificateFile /etc/letsencrypt/live/example.com/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem
SSLCertificateChainFile /etc/letsencrypt/live/example.com/fullchain.pem

ProxyPass / http://localhost:8443/
ProxyPassReverse / http://localhost:8443/
RequestHeader set X-Forwarded-Proto "https"
RequestHeader set X-Forwarded-Port "443"

```

but I got this when I tried to connect to [https://localhost](https://localhost)

```
503 proxy Error the proxy server received an invalid response from an upstream server.

```

Also Should I configure certificate location for Apache also or just tomcat 7.  
And How can I redirect any HTTP traffic to HTTPS.  
Any help!

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [March 3, 2018, 3:19am UTC](https://community.letsencrypt.org/t/how-to-configure-apahce-as-reverse-proxy-for-tomcat7/54674/2 "2018-03-03T03:19:29Z")

</div>

[https://localhost](https://localhost)  
doesn't match  
ServerName [example.com](http://example.com)  
ServerAlias \*.example.com  
So without any extra "effort" you will not get the content you desire that way.  
Try: [https://example.com](https://example.com)  
you should see: [http://localhost:8443](http://localhost:8443) content

> [@am0awad](#):
>
> I have configured my tomcat7 to use SSL successfully on port 8443.  
> Should I configure certificate location for Apache also or just tomcat 7.

If the server\_name is the same, then you only need one cert.  
If they can both access the same cert location, once cert and one location should be fine.  
You would only need an additional TLS connection for an additional listening port.  
In this case 8443 is already TLS, if you also want 443 to serve TLS, then you need to go through those motions.

> [@am0awad](#):
>
> How can I redirect any HTTP traffic to HTTPS.

A quick online search will show several ways.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 2, 2018, 3:19am UTC](https://community.letsencrypt.org/t/how-to-configure-apahce-as-reverse-proxy-for-tomcat7/54674/3 "2018-04-02T03:19:49Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
