Hmm, mod_rewrite should also do the job of detecting header.
We'll check if we can come up with a less resource-consuming solution.
On 28.10.08 21:09, "mikeytag" <[EMAIL PROTECTED]> wrote:
>
> The way I do it is to have nginx add an extra http header and then
> process that with either apache or php or something.
> Here is the relevant entry in our nginx.conf
>
> server {
> listen 443;
> ssl on;
> # path to your certificate
> ssl_certificate /etc/nginx/certs/godaddy_15_domain.crt;
> # path to your ssl key
> ssl_certificate_key /etc/nginx/certs/godaddy_15_domain.key;
>
> ssl_session_timeout 10m;
> ssl_session_cache shared:SSL:10m;
>
> ssl_protocols SSLv2 SSLv3 TLSv1;
> ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:
> +SSLv2:+EXP;
> ssl_prefer_server_ciphers on;
>
> location / {
> proxy_pass http://backend;
> proxy_buffering on;
>
> proxy_set_header Host $host;
> proxy_set_header X-Real-IP $remote_addr;
> proxy_set_header X-Forwarded-For
> $proxy_add_x_forwarded_for;
> proxy_set_header HTTPS on;
>
> client_max_body_size 10m;
> client_body_buffer_size 128k;
>
> proxy_connect_timeout 15;
> proxy_intercept_errors on;
> }
> }
>
> Here is the line to look for: proxy_set_header HTTPS on;
> Then in PHP I do this:
>
> if ($_SERVER['HTTP_HTTPS'] == 'on')
> {
> header('Location: http://www.blah.com');
> }
>
> Hope that helps.
> Mike
> On Oct 24, 9:46 am, sam lee <[EMAIL PROTECTED]> wrote:
>> Hi.
>>
>> I am using scalr.net paid service.
>> I am running 3 roles in my farm: app, www, and mysql
>> Let's say my domain is example.com
>>
>> I want to redirect:https://example.com/something-other-than-"secure"
>> tohttp://example.com/something-other-than-"secure"
>>
>> For example,https://example.com/hello/world
>> should be redirected tohttp://example.com/hello/world
>>
>> However,https://example.com/secure/whatever
>> should not be redirected to http://
>>
>> I first tried to do the redirect on Apache:
>> RewriteCond %{HTTPS} on
>> RewriteCond %{REQUEST_URI} !^/secure
>> RewriteRule ^(.*)$ http://%{SERVER_NAME}/$1 [R,L]
>>
>> But, since SSL is handled on nginx, apache only gets requests through
>> port 80. And, RewriteCond %{HTTPS} on is never true.
>> I also tried RewriteCond %{SERVER_PORT} 80, which is never true.
>>
>> So, I am trying to configure nginx to do the redirect I want.
>> My nginx.conf looks like:
>> http {
>> # ...
>> server {
>> listen 80;
>> # ... I did not edit this part
>> }
>> server { # SSL fromhttp://code.google.com/p/scalr/wiki/HTTPS
>> listen 443;
>> server_name _ *;
>>
>> ssl on;
>> ssl_certificate /etc/ssl/certs/host.crt;
>> ssl_certificate_key /etc/ssl/certs/host.key;
>>
>> ssl_session_timeout 10m;
>> ssl_session_cache shared:SSL:10m;
>>
>> ssl_protocols SSLv2 SSLv3 TLSv1;
>> ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:
>> +SSLv2:+EXP;
>> ssl_prefer_server_ciphers on;
>>
>> location /secure {
>> proxy_pass http://backend;
>> proxy_set_header Host $host;
>> proxy_set_header X-Real-IP $remote_addr;
>> proxy_set_header X-Forwarded-For
>> $proxy_add_x_forwarded_for;
>>
>> client_max_body_size 10m;
>> client_body_buffer_size 128k;
>>
>> proxy_buffering on;
>> proxy_connect_timeout 15;
>> proxy_intercept_errors on;
>> }
>> location / {
>> rewrite ^ http://$host$request_uri redirect;
>> }
>> }
>> }
>>
>> I am assuming location directives are matched top to bottom.
>> So, when the request uri does not match first "location /secure",
>> it'll always rewrite to http://$host$request_uri.
>>
>> But, above nginx.conf did not
>> redirecthttps://example.com/hello tohttp://example.com/hello.
>>
>> I also tried:
>> if ($request_uri !~ "^/secure") {
>> rewrite ^/(.*) http://$host$request_uri redirect;
>> }
>> instead of separate location directives. But still unsuccessful.
>>
>> Do you know how to redirect https:// to http:// ?
>>
>> Thank you.
>> Sam.
> >
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups
"scalr-discuss" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at
http://groups.google.com/group/scalr-discuss?hl=en
-~----------~----~----~----~------~----~------~--~---