The way I do it is to have nginx add an extra http header and then
process that with either apache or php or something.
Here is the relevant entry in our nginx.conf
server {
listen 443;
ssl on;
# path to your certificate
ssl_certificate /etc/nginx/certs/godaddy_15_domain.crt;
# path to your ssl key
ssl_certificate_key /etc/nginx/certs/godaddy_15_domain.key;
ssl_session_timeout 10m;
ssl_session_cache shared:SSL:10m;
ssl_protocols SSLv2 SSLv3 TLSv1;
ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:
+SSLv2:+EXP;
ssl_prefer_server_ciphers on;
location / {
proxy_pass http://backend;
proxy_buffering on;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For
$proxy_add_x_forwarded_for;
proxy_set_header HTTPS on;
client_max_body_size 10m;
client_body_buffer_size 128k;
proxy_connect_timeout 15;
proxy_intercept_errors on;
}
}
Here is the line to look for: proxy_set_header HTTPS on;
Then in PHP I do this:
if ($_SERVER['HTTP_HTTPS'] == 'on')
{
header('Location: http://www.blah.com');
}
Hope that helps.
Mike
On Oct 24, 9:46 am, sam lee <[EMAIL PROTECTED]> wrote:
> Hi.
>
> I am using scalr.net paid service.
> I am running 3 roles in my farm: app, www, and mysql
> Let's say my domain is example.com
>
> I want to redirect:https://example.com/something-other-than-"secure"
> tohttp://example.com/something-other-than-"secure"
>
> For example,https://example.com/hello/world
> should be redirected tohttp://example.com/hello/world
>
> However,https://example.com/secure/whatever
> should not be redirected to http://
>
> I first tried to do the redirect on Apache:
> RewriteCond %{HTTPS} on
> RewriteCond %{REQUEST_URI} !^/secure
> RewriteRule ^(.*)$ http://%{SERVER_NAME}/$1 [R,L]
>
> But, since SSL is handled on nginx, apache only gets requests through
> port 80. And, RewriteCond %{HTTPS} on is never true.
> I also tried RewriteCond %{SERVER_PORT} 80, which is never true.
>
> So, I am trying to configure nginx to do the redirect I want.
> My nginx.conf looks like:
> http {
> # ...
> server {
> listen 80;
> # ... I did not edit this part
> }
> server { # SSL fromhttp://code.google.com/p/scalr/wiki/HTTPS
> listen 443;
> server_name _ *;
>
> ssl on;
> ssl_certificate /etc/ssl/certs/host.crt;
> ssl_certificate_key /etc/ssl/certs/host.key;
>
> ssl_session_timeout 10m;
> ssl_session_cache shared:SSL:10m;
>
> ssl_protocols SSLv2 SSLv3 TLSv1;
> ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:
> +SSLv2:+EXP;
> ssl_prefer_server_ciphers on;
>
> location /secure {
> proxy_pass http://backend;
> proxy_set_header Host $host;
> proxy_set_header X-Real-IP $remote_addr;
> proxy_set_header X-Forwarded-For
> $proxy_add_x_forwarded_for;
>
> client_max_body_size 10m;
> client_body_buffer_size 128k;
>
> proxy_buffering on;
> proxy_connect_timeout 15;
> proxy_intercept_errors on;
> }
> location / {
> rewrite ^ http://$host$request_uri redirect;
> }
> }
> }
>
> I am assuming location directives are matched top to bottom.
> So, when the request uri does not match first "location /secure",
> it'll always rewrite to http://$host$request_uri.
>
> But, above nginx.conf did not
> redirecthttps://example.com/hello tohttp://example.com/hello.
>
> I also tried:
> if ($request_uri !~ "^/secure") {
> rewrite ^/(.*) http://$host$request_uri redirect;
> }
> instead of separate location directives. But still unsuccessful.
>
> Do you know how to redirect https:// to http:// ?
>
> Thank you.
> Sam.
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups
"scalr-discuss" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at
http://groups.google.com/group/scalr-discuss?hl=en
-~----------~----~----~----~------~----~------~--~---