nginx MQTT proxy with client certificate passthrough and TLS authentication in nginx

Viewed 355

I have a system composed by a client, a server and a nginx proxy between them. The client and the server use two communication flows:

  • HTTPS to access a web page.
  • MQTT with TLS authentication.

I want that the client authenticate the server with the nginx certificate (as nginx supports PKCS#11 and the server doesn't) but the client has to be authenticated by the server using the client's certificate (as this certificate acts as identification and authentication).

The thing is that in HTTPS this works fine. There is a TLS handshake between the client and nginx and then nginx uses proxy-pass to send the full TLS datagram to the server (with the client certificate in it).

But in the MQTT part nginx doesn't seem to send the client certificate.

I have this configuration.

stream{
log_format mqtt '$remote_addr [$time_local] $protocol $status $bytes_received ' 
            '$bytes_sent $upstream_addr';
server{

    listen  8883 ssl;
    listen [::]:8883 ssl;

    ssl_certificate "/etc/nginx/cert.pem";
    ssl_certificate_key "PKCS#11 URI";

    #ssl_preread on;
    proxy_pass thingsboard:8883;
    
    #proxy_ssl_session_reuse on;
    proxy_ssl on;
    #proxy_socket_keepalive on;
    #ssl_verify_client on;

    access_log /var/log/nginx/mqtt_access.log mqtt;
    error_log /var/log/nginx/mqtt_error.log;
}

}

The comments are things that I tried and didn't work.

0 Answers
Related