# Using certbot behind an SSL reverse proxy

**URL:** <https://community.letsencrypt.org/t/using-certbot-behind-an-ssl-reverse-proxy/36783>\
**Category:** Server\
**Created:** [June 25, 2017, 8:07am UTC](https://community.letsencrypt.org/t/using-certbot-behind-an-ssl-reverse-proxy/36783 "2017-06-25T08:07:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lauwenmark](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lauwenmark/32/14417_2.png) [@lauwenmark](https://community.letsencrypt.org/u/lauwenmark)\
**Post date:** [June 25, 2017, 8:07am UTC](https://community.letsencrypt.org/t/using-certbot-behind-an-ssl-reverse-proxy/36783/1 "2017-06-25T08:07:39Z")

</div>

Hello,

I've an Apache instance serving as a reverse proxy for various LAN-only hosts. Connection between the reverse proxy and the servers behind is in an untrusted space, so http cannot be used, only https. Here's a sample VHost at the reverse proxy level:

> \<VirtualHost \*:443\>  
> ServerName roundcube.ailesse.info  
> SSLEngine on  
> SSLProxyEngine on  
> ProxyPreserveHost on  
> SSLCertificateFile /etc/letsencrypt/live/roundcube.ailesse.info/fullchain.pem  
> SSLCertificateKeyFile /etc/letsencrypt/live/roundcube.ailesse.info/privkey.pem
> 
> ```
> ProxyPass / https://roundcube.ailesse.lan/
> ProxyPassReverse / https://roundcube.ailesse.lan/
> 
> Header always set Strict-Transport-Security "max-age=63072000; includeSubdomains;"
> <Proxy *>
> Order deny,allow
> Allow from all
> </Proxy>
> 
> ```

certbot works fine on the reverse proxy and can properly manage its certificates.

Now on the backend server, the VHost configuration is the following:

> \<VirtualHost \*:443\>  
> ServerName roundcube.ailesse.info  
> ServerAlias roundcube.ailesse.lan  
> SSLEngine on  
> SSLCertificateFile /etc/ssl/private/roundcube.ailesse.info.crt  
> SSLCertificateKeyFile /etc/ssl/private/roundcube.ailesse.info.key
> 
> ```
> <Directory /afs/ailesse.lan/service/www/info/ailesse/roundcube/roundcube/>
> Options Indexes FollowSymLinks MultiViews
> AllowOverride all
> RewriteEngine On
> Require all granted
> </Directory>
> 
> ```

When I try to run certbot on the backend server, I get the following error:

> certbot --apache -d roundcube.ailesse.info  
> Saving debug log to /var/log/letsencrypt/letsencrypt.log  
> Starting new HTTPS connection (1): [acme-v01.api.letsencrypt.org](http://acme-v01.api.letsencrypt.org)  
> Obtaining a new certificate  
> Performing the following challenges:  
> tls-sni-01 challenge for roundcube.ailesse.info  
> Waiting for verification...  
> Cleaning up challenges  
> Failed authorization procedure. roundcube.ailesse.info (tls-sni-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Incorrect validation certificate for tls-sni-01 challenge. Requested 03b9f3448b6a969e0a33a00c5d90662f.84c6040bfb7011d26bd19be8c62c44cd.acme.invalid from 91.121.52.222:443. Received 1 certificate(s), first certificate had names "\*.ailesse.info, ailesse.info"
> 
> IMPORTANT NOTES:
> 
> - The following errors were reported by the server:

I'm quite unsure on how to configure my system properly. I've searched for examples, but everytime a reverse proxy is used, it is always proxying through http, not https, between the proxy and the backend.

Can someone help me?

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [June 25, 2017, 8:46am UTC](https://community.letsencrypt.org/t/using-certbot-behind-an-ssl-reverse-proxy/36783/2 "2017-06-25T08:46:12Z")

</div>

By default certbot will use the tls-sni-01 method of verification, which won’t work behind a proxy. You’ll need to force http-01 webroot authentication instead.

```
 certbot certonly --webroot -w /var/www/html -d example.com
 certbot install --apache
```

---

<div class="post-metadata">

**Author:** ![lauwenmark](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lauwenmark/32/14417_2.png) [@lauwenmark](https://community.letsencrypt.org/u/lauwenmark)\
**Post date:** [June 25, 2017, 9:17am UTC](https://community.letsencrypt.org/t/using-certbot-behind-an-ssl-reverse-proxy/36783/3 "2017-06-25T09:17:15Z")

</div>

Ah, I should have figured it out, it is indeed working properly using your explanation.

Thanks a lot for your help !

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 25, 2017, 9:18am UTC](https://community.letsencrypt.org/t/using-certbot-behind-an-ssl-reverse-proxy/36783/4 "2017-07-25T09:18:07Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
