Ah I found the problem.
I was testing with self-signed certificate. So, firefox just displayed
security warning page without being redirected.
When I added my domain to exception in firefox, redirection worked just fine.
To summarize what I did on /etc/nginx/nginx.conf
server {
listen 80;
location /user {
rewrite ^ https://$host$request_uri? redirect;
}
location / {
...
}
...
}
server {
listen 443;
location /user {
...
}
location / {
rewrite ^ http://$host$request_uri? redirect;
}
...
}
On Tue, Oct 28, 2008 at 3:32 PM, Alex Kovalyov <[EMAIL PROTECTED]> wrote:
>
> Hmm, mod_rewrite should also do the job of detecting header.
> We'll check if we can come up with a less resource-consuming solution.
>
>
> On 28.10.08 21:09, "mikeytag" <[EMAIL PROTECTED]> wrote:
>
>>
>> The way I do it is to have nginx add an extra http header and then
>> process that with either apache or php or something.
>> Here is the relevant entry in our nginx.conf
>>
>> server {
>> listen 443;
>> ssl on;
>> # path to your certificate
>> ssl_certificate /etc/nginx/certs/godaddy_15_domain.crt;
>> # path to your ssl key
>> ssl_certificate_key /etc/nginx/certs/godaddy_15_domain.key;
>>
>> ssl_session_timeout 10m;
>> ssl_session_cache shared:SSL:10m;
>>
>> ssl_protocols SSLv2 SSLv3 TLSv1;
>> ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:
>> +SSLv2:+EXP;
>> ssl_prefer_server_ciphers on;
>>
>> location / {
>> proxy_pass http://backend;
>> proxy_buffering on;
>>
>> proxy_set_header Host $host;
>> proxy_set_header X-Real-IP $remote_addr;
>> proxy_set_header X-Forwarded-For
>> $proxy_add_x_forwarded_for;
>> proxy_set_header HTTPS on;
>>
>> client_max_body_size 10m;
>> client_body_buffer_size 128k;
>>
>> proxy_connect_timeout 15;
>> proxy_intercept_errors on;
>> }
>> }
>>
>> Here is the line to look for: proxy_set_header HTTPS on;
>> Then in PHP I do this:
>>
>> if ($_SERVER['HTTP_HTTPS'] == 'on')
>> {
>> header('Location: http://www.blah.com');
>> }
>>
>> Hope that helps.
>> Mike
>> On Oct 24, 9:46 am, sam lee <[EMAIL PROTECTED]> wrote:
>>> Hi.
>>>
>>> I am using scalr.net paid service.
>>> I am running 3 roles in my farm: app, www, and mysql
>>> Let's say my domain is example.com
>>>
>>> I want to redirect:https://example.com/something-other-than-"secure"
>>> tohttp://example.com/something-other-than-"secure"
>>>
>>> For example,https://example.com/hello/world
>>> should be redirected tohttp://example.com/hello/world
>>>
>>> However,https://example.com/secure/whatever
>>> should not be redirected to http://
>>>
>>> I first tried to do the redirect on Apache:
>>> RewriteCond %{HTTPS} on
>>> RewriteCond %{REQUEST_URI} !^/secure
>>> RewriteRule ^(.*)$ http://%{SERVER_NAME}/$1 [R,L]
>>>
>>> But, since SSL is handled on nginx, apache only gets requests through
>>> port 80. And, RewriteCond %{HTTPS} on is never true.
>>> I also tried RewriteCond %{SERVER_PORT} 80, which is never true.
>>>
>>> So, I am trying to configure nginx to do the redirect I want.
>>> My nginx.conf looks like:
>>> http {
>>> # ...
>>> server {
>>> listen 80;
>>> # ... I did not edit this part
>>> }
>>> server { # SSL fromhttp://code.google.com/p/scalr/wiki/HTTPS
>>> listen 443;
>>> server_name _ *;
>>>
>>> ssl on;
>>> ssl_certificate /etc/ssl/certs/host.crt;
>>> ssl_certificate_key /etc/ssl/certs/host.key;
>>>
>>> ssl_session_timeout 10m;
>>> ssl_session_cache shared:SSL:10m;
>>>
>>> ssl_protocols SSLv2 SSLv3 TLSv1;
>>> ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:
>>> +SSLv2:+EXP;
>>> ssl_prefer_server_ciphers on;
>>>
>>> location /secure {
>>> proxy_pass http://backend;
>>> proxy_set_header Host $host;
>>> proxy_set_header X-Real-IP $remote_addr;
>>> proxy_set_header X-Forwarded-For
>>> $proxy_add_x_forwarded_for;
>>>
>>> client_max_body_size 10m;
>>> client_body_buffer_size 128k;
>>>
>>> proxy_buffering on;
>>> proxy_connect_timeout 15;
>>> proxy_intercept_errors on;
>>> }
>>> location / {
>>> rewrite ^ http://$host$request_uri redirect;
>>> }
>>> }
>>> }
>>>
>>> I am assuming location directives are matched top to bottom.
>>> So, when the request uri does not match first "location /secure",
>>> it'll always rewrite to http://$host$request_uri.
>>>
>>> But, above nginx.conf did not
>>> redirecthttps://example.com/hello tohttp://example.com/hello.
>>>
>>> I also tried:
>>> if ($request_uri !~ "^/secure") {
>>> rewrite ^/(.*) http://$host$request_uri redirect;
>>> }
>>> instead of separate location directives. But still unsuccessful.
>>>
>>> Do you know how to redirect https:// to http:// ?
>>>
>>> Thank you.
>>> Sam.
>> >
>
>
>
> >
>
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups
"scalr-discuss" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at
http://groups.google.com/group/scalr-discuss?hl=en
-~----------~----~----~----~------~----~------~--~---