NGINX as forward proxy for https to another proxyserver

Viewed 84

We have an application server on intranet that needs to access different 3th party API's (https). In between there is a proxy server (which we don't support) to access this 3th party. This works fine but due to limitation on the standard application software we can only send 1 outgoing certificate. So we can make it work for 1 3th party API but not the other ones.

I'm trying now to install an nginx server between them and configure nginx as a forward proxy to the other proxy server. So basically it will be: application -> nginx -> proxyserver -> 3th party

I tried several different configurations already but still without any success My latest config now is:

server {
  listen 80;

  resolver 8.8.8.8;

  #forward proxy for CONNECT request
  proxy_connect;
  proxy_connect_allow            443 563;
  proxy_connect_connect_timeout  10s;
  proxy_connect_read_timeout     10s;
  proxy_connect_send_timeout     10s;
  #proxy_connect_address X.X.X.X:PORT;
  proxy_connect_bind $remote_addr transparent;

location /api1 {

    proxy_pass http://X.X.X.X:PORT;

    proxy_ssl_certificate     api1.crt;
    proxy_ssl_certificate_key api1.key;            
  }

location /api2 {

    proxy_pass http://X.X.X.X:PORT;

    proxy_ssl_certificate     api2.crt;
    proxy_ssl_certificate_key api2.key;            
  }

First of all when trying to curl the request

curl --proxy xxxx:80 -X POST -d .... https://3thparty.com/api/request

I receive an SSL Connect error.

And I don't even know if it would be possible to send a different certificate to the other 3th party. Does someone have an idea how to fix this? Or a suggestion for another solution? Much appreciated!

0 Answers
Related