# Proxy Protocol Causing Issues with Non-HTTPS Requests

**URL:** <https://discuss.pomerium.com/t/proxy-protocol-causing-issues-with-non-https-requests/437>\
**Category:** Support\
**Created:** [December 17, 2024, 10:52am UTC](https://discuss.pomerium.com/t/proxy-protocol-causing-issues-with-non-https-requests/437 "2024-12-17T10:52:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![renatomjr](https://avatars.discourse-cdn.com/v4/letter/r/eada6e/32.png) [@renatomjr](https://discuss.pomerium.com/u/renatomjr)\
**Post date:** [December 17, 2024, 10:52am UTC](https://discuss.pomerium.com/t/proxy-protocol-causing-issues-with-non-https-requests/437/1 "2024-12-17T10:52:38Z")

</div>

When enabling the proxy protocol on both the AWS NLB and the Pomerium Ingress Controller, all non-HTTPS requests (handled by the redirect server) return a 400 Bad Request error. This behavior is preventing ACME HTTP-01 challenges from functioning correctly.

Has anyone encountered this issue before or found a workaround to make ACME HTTP-01 challenges work in this setup?

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [December 17, 2024, 6:34pm UTC](https://discuss.pomerium.com/t/proxy-protocol-causing-issues-with-non-https-requests/437/2 "2024-12-17T18:34:29Z")

</div>

I have not attempted to do this. Is the AWS NLB also terminating port 80 traffic? And is it also using the proxy protocol for this traffic to Pomerium (not just the HTTPS traffic but also the HTTP traffic)?

I believe the Pomerium redirect server does not support the proxy protocol. This might explain the issue. I suppose this would be a bug and if `use_proxy_protocol` is set it should also apply to the redirect server. I can create an issue if this sounds like what’s wrong.

Possible workarounds:

1. Could you disable the proxy protocol just for port 80 traffic?
2. Could you implement the redirect in a different way? Does the NLB support doing HTTP to HTTPS redirects?

---

<div class="post-metadata">

**Author:** ![renatomjr](https://avatars.discourse-cdn.com/v4/letter/r/eada6e/32.png) [@renatomjr](https://discuss.pomerium.com/u/renatomjr)\
**Post date:** [December 18, 2024, 10:00am UTC](https://discuss.pomerium.com/t/proxy-protocol-causing-issues-with-non-https-requests/437/3 "2024-12-18T10:00:44Z")

</div>

Thank you for your reply.

Yes, the AWS NLB is terminating traffic on port 80 and using the proxy protocol for HTTP traffic.

Regarding the workarounds:

1. As far as I know, there is currently no way to enable or disable the proxy protocol for a specific port (or target group) when using a Kubernetes Service of type LoadBalancer.
2. Unfortunately, it does not seem possible.

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [December 19, 2024, 5:48pm UTC](https://discuss.pomerium.com/t/proxy-protocol-causing-issues-with-non-https-requests/437/4 "2024-12-19T17:48:07Z")

</div>

Thanks for the update. I created this issue [http\_redirect\_addr incompatible use\_proxy\_protocol · Issue #5403 · pomerium/pomerium · GitHub](https://github.com/pomerium/pomerium/issues/5403).

I agree that the redirect server should also be using the proxy protocol. We will need to update the code.

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [December 23, 2024, 2:47pm UTC](https://discuss.pomerium.com/t/proxy-protocol-causing-issues-with-non-https-requests/437/5 "2024-12-23T14:47:49Z")

</div>

Hi @renatomjr ,

A fix for this was [merged to main](https://github.com/pomerium/pomerium/commit/b3d2ef95e7b3f4af6f8f60bfd2b5105fe72cea96). It should make the http redirect server understand the proxy protocol. We will be doing a release in the new year that will include these changes.

While working on this I discovered that autocert is not compatible with the proxy protocol. The library we use to provision certificates doesn’t have the flexibility we need to get it to work, so fixing that problem is a bigger project. If autocert is needed, a workaround is to use Pomerium Zero [custom domains](https://www.pomerium.com/docs/capabilities/custom-domains#custom-domains), which can provision certificates via DNS records.

---

<div class="post-metadata">

**Author:** ![akhayyat](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/akhayyat/32/185_2.png) [@akhayyat](https://discuss.pomerium.com/u/akhayyat)\
**Post date:** [March 8, 2026, 2:32am UTC](https://discuss.pomerium.com/t/proxy-protocol-causing-issues-with-non-https-requests/437/6 "2026-03-08T02:32:41Z")

</div>

I realize this has been fixed long ago, but I’m seeing the same exact symptoms with v0.32.0 on OCI (Oracle cloud): enabling proxy protocol while using the network load-balancer causes http (non-https) requests to return 400 errors, breaking ACME HTTP01 challenges.

Any clue why would this be happening? Any suggestions for how to debug this?

Requests to the HTTP01 challenge URLs on the internal k8s endpoint works correctly. Any requests through the network load-balancer return 400 errors.
