Haproxy with multiple CA configuration

Viewed 2070

SSL newbie here, using haproxy 1.8, having a situation when I have 2 aws API Gateways pointing to the same proxy server and 2 clients certificates generated by api gateway itself assigned one to each gateways.

Now I have a haproxy server that I'm trying to configure in a way to only allow access from these 2 api gateways.

When I do it for api gateway only, meaning I only set the ca-file to a file containing 1 client certificate, it works just fine as expected but I don't know how to set both client certificates to be allowed.

so I have these files setup:

  • haproxy.pem which contains
    • server cert issued by go daddy
    • private key
    • go daddy certs
  • api-gw.pem first client cert which was copied from api gateway
  • api-gw2.pem second client cert which was copied from api gateway
  • client-certs.crt which is a concatenated version of api-gw.pem and api-gw2.pem

when I bind ssl like below for client cert, it works just fine:

bind :443 ssl crt /etc/haproxy/haproxy.pem verify required ca-file /etc/haproxy/api-gw.pem

or

bind :443 ssl crt /etc/haproxy/haproxy.pem verify required ca-file /etc/haproxy/api-gw2.pem

for each of the bindings above only the correct api gateway can access the proxy and the other one can't.

but when I do as below to allow both access the proxy server, it only allows the first client cert even though the file contains both:

bind :443 ssl crt /etc/haproxy/haproxy.pem verify required ca-file /etc/haproxy/client-certs.pem

As my knowledge is limited when it comes to certificates and ssl, I'm not sure if it would work to put multiple client certificates into one file but from what I've read in internet, it's suggested that way... I still don't know why wouldn't it work though.

EDIT I Michael suggested, I put both client certs together using the

cat api-gw.pem api-gw2.pem > api-gw-combo.pem

and the combo file looks like:

-----BEGIN CERTIFICATE-----
.....cert content for api-gw
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
.....cert content for api-gw2
-----END CERTIFICATE-----

but same as my initial file client-certs.crt, haproxy still accepts the first cert only.

0 Answers
Related