Ah I found the problem.
I was testing with self-signed certificate. So, firefox just displayed
security warning page without being redirected.
When I added my domain to exception in firefox, redirection worked just fine.

To summarize what I did on /etc/nginx/nginx.conf

server {
    listen 80;
    location /user {
        rewrite ^ https://$host$request_uri? redirect;
    }
    location / {
    ...
    }
    ...
}
server {
    listen 443;
    location /user {
    ...
    }
    location / {
        rewrite ^ http://$host$request_uri? redirect;
    }
    ...
}

On Tue, Oct 28, 2008 at 3:32 PM, Alex Kovalyov <[EMAIL PROTECTED]> wrote:
>
> Hmm, mod_rewrite should also do the job of detecting header.
> We'll check if we can come up with a less resource-consuming solution.
>
>
> On 28.10.08 21:09, "mikeytag" <[EMAIL PROTECTED]> wrote:
>
>>
>> The way I do it is to have nginx add an extra http header and then
>> process that with either apache or php or something.
>> Here is the relevant entry in our nginx.conf
>>
>> server {
>>         listen 443;
>>         ssl on;
>>         # path to your certificate
>>         ssl_certificate /etc/nginx/certs/godaddy_15_domain.crt;
>>         # path to your ssl key
>>         ssl_certificate_key /etc/nginx/certs/godaddy_15_domain.key;
>>
>>         ssl_session_timeout     10m;
>>         ssl_session_cache       shared:SSL:10m;
>>
>>         ssl_protocols  SSLv2 SSLv3 TLSv1;
>>         ssl_ciphers  ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:
>> +SSLv2:+EXP;
>>         ssl_prefer_server_ciphers   on;
>>
>>         location /    {
>>             proxy_pass         http://backend;
>>             proxy_buffering    on;
>>
>>             proxy_set_header   Host             $host;
>>             proxy_set_header   X-Real-IP        $remote_addr;
>>             proxy_set_header   X-Forwarded-For
>> $proxy_add_x_forwarded_for;
>>             proxy_set_header   HTTPS            on;
>>
>>             client_max_body_size       10m;
>>             client_body_buffer_size    128k;
>>
>>             proxy_connect_timeout 15;
>>             proxy_intercept_errors on;
>>         }
>>     }
>>
>> Here is the line to look for: proxy_set_header   HTTPS            on;
>> Then in PHP I do this:
>>
>> if ($_SERVER['HTTP_HTTPS'] == 'on')
>> {
>>    header('Location: http://www.blah.com');
>> }
>>
>> Hope that helps.
>> Mike
>> On Oct 24, 9:46 am, sam lee <[EMAIL PROTECTED]> wrote:
>>> Hi.
>>>
>>> I am using scalr.net paid service.
>>> I am running 3 roles in my farm: app, www, and mysql
>>> Let's say my domain is example.com
>>>
>>> I want to redirect:https://example.com/something-other-than-"secure";
>>> tohttp://example.com/something-other-than-"secure";
>>>
>>> For example,https://example.com/hello/world
>>> should be redirected tohttp://example.com/hello/world
>>>
>>> However,https://example.com/secure/whatever
>>> should not be redirected to http://
>>>
>>> I first tried to do the redirect on Apache:
>>> RewriteCond %{HTTPS} on
>>> RewriteCond %{REQUEST_URI} !^/secure
>>> RewriteRule ^(.*)$  http://%{SERVER_NAME}/$1 [R,L]
>>>
>>> But, since SSL is handled on nginx, apache only gets requests through
>>> port 80. And, RewriteCond %{HTTPS} on is never true.
>>> I also tried RewriteCond %{SERVER_PORT} 80, which is never true.
>>>
>>> So, I am trying to configure nginx to do the redirect I want.
>>> My nginx.conf looks like:
>>>     http {
>>>         # ...
>>>         server {
>>>             listen 80;
>>>             # ... I did not edit this part
>>>         }
>>>         server {  # SSL fromhttp://code.google.com/p/scalr/wiki/HTTPS
>>>             listen 443;
>>>             server_name  _ *;
>>>
>>>             ssl                  on;
>>>             ssl_certificate      /etc/ssl/certs/host.crt;
>>>             ssl_certificate_key  /etc/ssl/certs/host.key;
>>>
>>>             ssl_session_timeout  10m;
>>>             ssl_session_cache    shared:SSL:10m;
>>>
>>>             ssl_protocols  SSLv2 SSLv3 TLSv1;
>>>             ssl_ciphers  ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:
>>> +SSLv2:+EXP;
>>>             ssl_prefer_server_ciphers   on;
>>>
>>>             location /secure {
>>>                 proxy_pass        http://backend;
>>>                 proxy_set_header   Host             $host;
>>>                 proxy_set_header   X-Real-IP        $remote_addr;
>>>                 proxy_set_header   X-Forwarded-For
>>> $proxy_add_x_forwarded_for;
>>>
>>>                 client_max_body_size       10m;
>>>                 client_body_buffer_size    128k;
>>>
>>>                 proxy_buffering on;
>>>                 proxy_connect_timeout 15;
>>>                 proxy_intercept_errors on;
>>>             }
>>>             location / {
>>>                 rewrite ^ http://$host$request_uri redirect;
>>>             }
>>>         }
>>>     }
>>>
>>> I am assuming location directives are matched top to bottom.
>>> So, when the request uri does not match first "location /secure",
>>> it'll always rewrite to http://$host$request_uri.
>>>
>>> But, above nginx.conf did not
>>> redirecthttps://example.com/hello tohttp://example.com/hello.
>>>
>>> I also tried:
>>>     if ($request_uri !~ "^/secure") {
>>>         rewrite ^/(.*) http://$host$request_uri redirect;
>>>     }
>>> instead of separate location directives. But still unsuccessful.
>>>
>>> Do you know how to redirect https:// to http:// ?
>>>
>>> Thank you.
>>> Sam.
>> >
>
>
>
> >
>

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"scalr-discuss" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/scalr-discuss?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to