<div dir="ltr">I have a similar setup, running under Kubernetes so there is HAProxy in front of Nginx which is a reverse proxy to the IdP. I didn't seem to have issues quite as severe but I did enable proxy protocol on the HAProxy and again in the Nginx configuration to allow for logging of client ip addresses in the logs but that probably won't be relevant to you if Nginx is the first service your clients connect to.<div><br></div><div>I'm using Jetty and LE certs. I'm using the Unicon Shibboleth IdP image with very minor changes mostly related to UI customization and for making it a bit easier to load secrets out of Kubernetes into the IdP config.</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jun 7, 2019 at 11:26 AM Mert Metin <<a href="mailto:mert@proximify.ca">mert@proximify.ca</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div style="overflow-wrap: break-word;">Hello everybody,<div><br></div><div>I am having trouble to use reverse-proxy with Shibboleth IDP.</div><div>Let me give some details:</div><div><br></div><div>I have a server with bunch of dockers — a docker for reverse proxy with NGINX, a docker for Shibboleth SP and Shibboleth IDP. SP is served over <a href="http://sp.example.com" target="_blank">sp.example.com</a> and IDP is served over <a href="http://idp.example.com" target="_blank">idp.example.com</a>. Both URLs have valid SSL certificate from Let’s encrypt.</div><div><br></div><div>SP works perfectly fine. However, I am having trouble for the IDP.</div><div>Whenever I go to, <a href="http://idp.example.com" target="_blank">idp.example.com</a>, Chrome gives <span style="color:rgb(100,100,100);font-size:0.8em;text-transform:uppercase;font-family:system-ui,sans-serif;background-color:rgb(255,255,255)">ERR_INVALID_RESPONSE</span></div><div>When I try with Safari, it downloads a single file — and that file includes a single letter “P”. Weird, right?</div><div><br></div><div>I go through logs of both Shibboleth IDP and NGINX. The IDP logs doesn’t show any error. However, NGINX shows the error below:</div><div><br></div><div><div style="margin:0px;font-stretch:normal;font-size:11px;line-height:normal;font-family:Menlo;color:rgb(195,55,32);background-color:rgb(255,255,255)"><span style="font-variant-ligatures:no-common-ligatures"><b>upstream sent no valid HTTP/1.0 header while reading response header from upstream</b></span></div></div><div style="margin:0px;font-stretch:normal;font-size:11px;line-height:normal;font-family:Menlo;color:rgb(195,55,32);background-color:rgb(255,255,255)"><br></div><div><br></div><div>It looks like Tomcat or Jetty in iDP container doesn’t return a proper HTTP header — or response? </div><div><br></div><div>I searched through this error. However, I didn’t get anywhere. Does anyone have an idea?</div><div><br></div></div>-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div><p style="margin-bottom:0in;line-height:13px"><font color="#ff0000"><font face="arial, sans-serif"><font style="font-size:10pt"><b>Darren Boss</b></font></font></font></p><font style="font-size:10pt"><i>Senior Programmer/Analyst</i></font><font style="font-size:10pt"><i><br>Programmeur-analyste principal</i></font><font style="font-size:10pt"><i><br><a href="mailto:darren.boss@computecanada.ca" style="color:rgb(17,85,204)" target="_blank">darren.boss@computecanada.ca</a></i></font><font style="font-size:10pt"><i><br>(o) 416.228.1234 x </i></font><font color="#000000"><font style="font-size:10pt">230</font></font></div></div></div></div></div></div>