Hey All, I recently started to use ISPconfig, tried it a few years ago but never found the time. Here I am, starting to use. Anyhow, I can't wrap my head around a small issue. The default admin frontend is reached on port 8080. (<myip:8080>) I am running HAproxy using Pfsense and it always works but not for ISPconfig. I set; ip, port and ssl checkmark for the backend for the frontend I choose sub.domain.com and tell it to use the backend which could be reached on port 443. When I reach the specified sub.domain.com I get error 400 and it's done. How to fix that? Why is it not working ? Thanks, Dennis
Thanks for your reply! Backend: Frontend acl: Frontend action: Normally this would be enough. For some webservices I need to fiddle with the config on the webserver side like specify fqdn. edit: posted this from my phone. images may look very bad
I get the following error. Code: [Wed Aug 03 07:32:23.361782 2022] [mpm_event:notice] [pid 532339:tid 140717988535360] AH00491: caught SIGTERM, shutting down [ 2022-08-03 07:32:23.3623 532355/7fca4fcfb700 age/Ust/UstRouterMain.cpp:421 ]: Signal received. Gracefully shutting down... (send signal 2 more time(s) to force shutdown) [ 2022-08-03 07:32:23.3623 532346/7fc904b9d700 age/Cor/CoreMain.cpp:531 ]: Signal received. Gracefully shutting down... (send signal 2 more time(s) to force shutdown) [ 2022-08-03 07:32:23.3624 532355/7fca4fdcfe40 age/Ust/UstRouterMain.cpp:491 ]: Received command to shutdown gracefully. Waiting until all clients have disconnected... [ 2022-08-03 07:32:23.3624 532346/7fc90554be40 age/Cor/CoreMain.cpp:900 ]: Received command to shutdown gracefully. Waiting until all clients have disconnected... [ 2022-08-03 07:32:23.3624 532355/7fca4fcfb700 Ser/Server.h:464 ]: [UstRouter] Shutdown finished [ 2022-08-03 07:32:23.3625 532355/7fca4f479700 Ser/Server.h:816 ]: [UstRouterApiServer] Freed 0 spare client objects [ 2022-08-03 07:32:23.3625 532355/7fca4f479700 Ser/Server.h:464 ]: [UstRouterApiServer] Shutdown finished [ 2022-08-03 07:32:23.3627 532346/7fc8effff700 Ser/Server.h:816 ]: [ServerThr.2] Freed 128 spare client objects [ 2022-08-03 07:32:23.3627 532346/7fc8effff700 Ser/Server.h:464 ]: [ServerThr.2] Shutdown finished [ 2022-08-03 07:32:23.3629 532346/7fc8ef7fe700 Ser/Server.h:816 ]: [ServerThr.3] Freed 128 spare client objects [ 2022-08-03 07:32:23.3629 532346/7fc8ef7fe700 Ser/Server.h:464 ]: [ServerThr.3] Shutdown finished [ 2022-08-03 07:32:23.3631 532346/7fc8eeffd700 Ser/Server.h:816 ]: [ServerThr.4] Freed 128 spare client objects [ 2022-08-03 07:32:23.3631 532346/7fc8eeffd700 Ser/Server.h:464 ]: [ServerThr.4] Shutdown finished [ 2022-08-03 07:32:23.3633 532355/7fca4fdcfe40 age/Ust/UstRouterMain.cpp:523 ]: Passenger UstRouter shutdown finished [ 2022-08-03 07:32:23.3634 532346/7fc904b9d700 Ser/Server.h:816 ]: [ServerThr.1] Freed 128 spare client objects [ 2022-08-03 07:32:23.3634 532346/7fc904b9d700 Ser/Server.h:464 ]: [ServerThr.1] Shutdown finished [ 2022-08-03 07:32:23.3636 532346/7fc8ee7fc700 Ser/Server.h:816 ]: [ApiServer] Freed 0 spare client objects [ 2022-08-03 07:32:23.3636 532346/7fc8ee7fc700 Ser/Server.h:464 ]: [ApiServer] Shutdown finished [ 2022-08-03 07:32:23.3670 532346/7fc904b9d700 age/Cor/CoreMain.cpp:531 ]: Signal received. Gracefully shutting down... (send signal 1 more time(s) to force shutdown) [ 2022-08-03 07:32:23.4232 532346/7fc90554be40 age/Cor/CoreMain.cpp:967 ]: Passenger core shutdown finished [Wed Aug 03 07:32:23.599682 2022] [ssl:error] [pid 532858:tid 140160398257216] AH02217: ssl_stapling_init_cert: can't retrieve issuer certificate! [subject: CN=*.mydomain.com / issuer: CN=R3,O=Let's Encrypt,C=US / serial: 03DECB8278C0DFAC271CBFD5B4912FED75C7 / notbefore: Jun 30 00:17:02 2022 GMT / notafter: Sep 28 00:17:01 2022 GMT] [Wed Aug 03 07:32:23.599814 2022] [ssl:error] [pid 532858:tid 140160398257216] AH02604: Unable to configure certificate sub.mydomain.com:8081:0 for stapling [ 2022-08-03 07:32:23.6282 532866/7fadee40ae40 age/Wat/WatchdogMain.cpp:1291 ]: Starting Passenger watchdog... [ 2022-08-03 07:32:23.6605 532869/7f9a5e46fe40 age/Cor/CoreMain.cpp:982 ]: Starting Passenger core... [ 2022-08-03 07:32:23.6608 532869/7f9a5e46fe40 age/Cor/CoreMain.cpp:235 ]: Passenger core running in multi-application mode. [ 2022-08-03 07:32:23.6657 532869/7f9a5e46fe40 age/Cor/CoreMain.cpp:732 ]: Passenger core online, PID 532869 [ 2022-08-03 07:32:23.7012 532876/7f6a61e21e40 age/Ust/UstRouterMain.cpp:529 ]: Starting Passenger UstRouter... [ 2022-08-03 07:32:23.7066 532876/7f6a61e21e40 age/Ust/UstRouterMain.cpp:342 ]: Passenger UstRouter online, PID 532876 [Wed Aug 03 07:32:23.707437 2022] [suexec:notice] [pid 532858:tid 140160398257216] AH01232: suEXEC mechanism enabled (wrapper: /usr/lib/apache2/suexec) [ 2022-08-03 07:32:23.7203 532876/7f6a61d4d700 age/Ust/UstRouterMain.cpp:421 ]: Signal received. Gracefully shutting down... (send signal 2 more time(s) to force shutdown) [ 2022-08-03 07:32:23.7203 532869/7f9a5dac1700 age/Cor/CoreMain.cpp:531 ]: Signal received. Gracefully shutting down... (send signal 2 more time(s) to force shutdown) [ 2022-08-03 07:32:23.7203 532876/7f6a61e21e40 age/Ust/UstRouterMain.cpp:491 ]: Received command to shutdown gracefully. Waiting until all clients have disconnected... [ 2022-08-03 07:32:23.7204 532869/7f9a5e46fe40 age/Cor/CoreMain.cpp:900 ]: Received command to shutdown gracefully. Waiting until all clients have disconnected... [ 2022-08-03 07:32:23.7206 532869/7f9a5d23f700 Ser/Server.h:816 ]: [ServerThr.2] Freed 128 spare client objects [ 2022-08-03 07:32:23.7207 532869/7f9a5d23f700 Ser/Server.h:464 ]: [ServerThr.2] Shutdown finished [ 2022-08-03 07:32:23.7207 532869/7f9a377fe700 Ser/Server.h:816 ]: [ApiServer] Freed 0 spare client objects [ 2022-08-03 07:32:23.7208 532869/7f9a377fe700 Ser/Server.h:464 ]: [ApiServer] Shutdown finished [ 2022-08-03 07:32:23.7208 532876/7f6a61d4d700 Ser/Server.h:464 ]: [UstRouter] Shutdown finished [ 2022-08-03 07:32:23.7209 532869/7f9a5c9bd700 Ser/Server.h:816 ]: [ServerThr.3] Freed 128 spare client objects [ 2022-08-03 07:32:23.7209 532876/7f6a614cb700 Ser/Server.h:816 ]: [UstRouterApiServer] Freed 0 spare client objects [ 2022-08-03 07:32:23.7209 532869/7f9a5c9bd700 Ser/Server.h:464 ]: [ServerThr.3] Shutdown finished [ 2022-08-03 07:32:23.7209 532876/7f6a614cb700 Ser/Server.h:464 ]: [UstRouterApiServer] Shutdown finished [ 2022-08-03 07:32:23.7210 532869/7f9a37fff700 Ser/Server.h:816 ]: [ServerThr.4] Freed 128 spare client objects [ 2022-08-03 07:32:23.7211 532869/7f9a37fff700 Ser/Server.h:464 ]: [ServerThr.4] Shutdown finished [ 2022-08-03 07:32:23.7211 532869/7f9a5dac1700 Ser/Server.h:816 ]: [ServerThr.1] Freed 128 spare client objects [ 2022-08-03 07:32:23.7211 532869/7f9a5dac1700 Ser/Server.h:464 ]: [ServerThr.1] Shutdown finished [ 2022-08-03 07:32:23.7222 532876/7f6a61e21e40 age/Ust/UstRouterMain.cpp:523 ]: Passenger UstRouter shutdown finished [Wed Aug 03 07:32:23.770194 2022] [ssl:error] [pid 532897:tid 140160398257216] AH02217: ssl_stapling_init_cert: can't retrieve issuer certificate! [subject: CN=*.mydomain.com / issuer: CN=R3,O=Let's Encrypt,C=US / serial: 03DECB8278C0DFAC271CBFD5B4912FED75C7 / notbefore: Jun 30 00:17:02 2022 GMT / notafter: Sep 28 00:17:01 2022 GMT] [Wed Aug 03 07:32:23.770235 2022] [ssl:error] [pid 532897:tid 140160398257216] AH02604: Unable to configure certificate sub.mydomain.com:8081:0 for stapling [ 2022-08-03 07:32:23.7849 532869/7f9a5e46fe40 age/Cor/CoreMain.cpp:967 ]: Passenger core shutdown finished [ 2022-08-03 07:32:23.8014 532901/7f4c62006e40 age/Wat/WatchdogMain.cpp:1291 ]: Starting Passenger watchdog... [ 2022-08-03 07:32:23.8373 532905/7f3a10a5ce40 age/Cor/CoreMain.cpp:982 ]: Starting Passenger core... [ 2022-08-03 07:32:23.8376 532905/7f3a10a5ce40 age/Cor/CoreMain.cpp:235 ]: Passenger core running in multi-application mode. [ 2022-08-03 07:32:23.8433 532905/7f3a10a5ce40 age/Cor/CoreMain.cpp:732 ]: Passenger core online, PID 532905 [ 2022-08-03 07:32:23.8707 532913/7f6cbd175e40 age/Ust/UstRouterMain.cpp:529 ]: Starting Passenger UstRouter... [ 2022-08-03 07:32:23.8726 532913/7f6cbd175e40 age/Ust/UstRouterMain.cpp:342 ]: Passenger UstRouter online, PID 532913 [Wed Aug 03 07:32:23.873557 2022] [:error] [pid 532897:tid 140160398257216] python_init: Python version mismatch, expected '2.7.17', found '2.7.18'. [Wed Aug 03 07:32:23.873768 2022] [:error] [pid 532897:tid 140160398257216] python_init: Python executable found ''. [Wed Aug 03 07:32:23.873810 2022] [:error] [pid 532897:tid 140160398257216] python_init: Python path being used '/lib/python2.7:/lib/python2.7/plat-x86_64-linux-gnu:/lib/python2.7/lib-tk:/lib/python2.7/lib-old:/lib/python2.7/lib-dynload'. [Wed Aug 03 07:32:23.873890 2022] [:notice] [pid 532897:tid 140160398257216] mod_python: Creating 8 session mutexes based on 6 max processes and 25 max threads. [Wed Aug 03 07:32:23.873913 2022] [:notice] [pid 532897:tid 140160398257216] mod_python: using mutex_directory /tmp [Wed Aug 03 07:32:23.902568 2022] [mpm_event:notice] [pid 532897:tid 140160398257216] AH00489: Apache/2.4.41 (Ubuntu) mod_fcgid/2.3.9 OpenSSL/1.1.1f Phusion_Passenger/5.0.30 mod_python/3.3.1 Python/2.7.18 configured -- resuming normal operations [Wed Aug 03 07:32:23.902634 2022] [core:notice] [pid 532897:tid 140160398257216] AH00094: Command line: '/usr/sbin/apache2'
That should be ok so far, the SSL stapling is uncritical. Which line do you get in the access.log when accessing the panel?
So I disabled SSL from the vhost config, it's working now. I am thinking about leaving it disabled, since the frontend is SSL.
If the connection between proxy and ISPConfig is internally and you trust it, then that's probably ok.
It's in the same network. should be safe, at least I hope so. Otherwise the whole proxy thing is useless :O Thanks for your help!