Add SNI note to proxy example

This commit is contained in:
Francis Lavoie 2023-11-19 01:16:46 -05:00
parent 2c3fb1aa38
commit 528b1c191f
No known key found for this signature in database
GPG key ID: C5204D4F28147FC8

View file

@ -735,12 +735,13 @@ reverse_proxy 10.0.0.1:443 {
```
Instead you may establish trust with the upstream by explicitly [trusting the upstream's certificate](#tls_trusted_ca_certs):
Instead you may establish trust with the upstream by explicitly [trusting the upstream's certificate](#tls_trusted_ca_certs), and (optionally) setting TLS-SNI to match the hostname in the upstream's certificate:
```caddy-d
reverse_proxy 10.0.0.1:443 {
transport http {
tls_trusted_ca_certs /path/to/cert.pem
tls_server_name app.example.com
}
}
```