<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="https://uname.pingveno.net/blog/index.php/feed/rss2/xslt" ?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title># uname -a - Mot-clé - https</title>
    <link>https://uname.pingveno.net/blog/index.php/</link>
    <atom:link href="https://uname.pingveno.net/blog/index.php/feed/tag/https/rss2" rel="self" type="application/rss+xml" />
    <description>Le blog de uname.pingveno.net</description>
    <language>fr</language>
    <pubDate>Tue, 18 Aug 2026 13:46:21 +0200</pubDate>
    <copyright>Mathieu Pellegrin</copyright>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <generator>Dotclear</generator>
          <item>
        <title>Wordpress : la revanche du reverse proxy</title>
        <link>https://uname.pingveno.net/blog/index.php/post/2020/01/23/Wordpress-%3A-la-revanche-du-reverse-proxy</link>
        <guid isPermaLink="false">urn:md5:7efb045bd6818357ae77177b2af27e60</guid>
        <pubDate>Thu, 23 Jan 2020 23:30:00 +0100</pubDate>
        <dc:creator>Mathieu</dc:creator>
                          <category>https</category>
                  <category>online.net</category>
                  <category>scaleway</category>
                  <category>ssl</category>
                  <category>wordpress</category>
                <description>          &lt;p&gt;Quand un reverse proxy est mal configuré,&lt;/p&gt;

&lt;p&gt;Il n'a pas les bonnes variables d'environnement,&lt;/p&gt;

&lt;p&gt;Wordpress se croit toujours en HTTP,&lt;/p&gt;

&lt;p&gt;Et fait une boucle de redirection en HTTPS.&lt;/p&gt;

&lt;p&gt;Heureusement, il y a une autre solution,&lt;/p&gt;

&lt;p&gt;Ouvrez wp-config.php, et ajoutez (au bon endroit) :&lt;/p&gt;

&lt;pre&gt;
/* Turn HTTPS 'on' if HTTP_X_FORWARDED_PROTO matches 'https' */
if (strpos($_SERVER['HTTP_X_FORWARDED_PROTO'], 'https') !== false) {
    $_SERVER['HTTPS'] = 'on';
}&lt;/pre&gt;

&lt;p&gt;&lt;code&gt;&lt;a href=&quot;https://wordpress.stackexchange.com/a/250254&quot;&gt;Source&lt;/a&gt;.&lt;/code&gt;&lt;/p&gt;</description>
        
              </item>
          <item>
        <title>Apache : globally configure HTTPS for all VirtualHosts</title>
        <link>https://uname.pingveno.net/blog/index.php/post/2013/01/25/Apache-%3A-globally-configure-HTTPS-for-all-VirtualHosts</link>
        <guid isPermaLink="false">urn:md5:fe226c3e55b5ee9393d47508ef2ebab3</guid>
        <pubDate>Sat, 16 Mar 2013 19:16:00 +0100</pubDate>
        <dc:creator>Mathieu</dc:creator>
                  <category>Hacks</category>
                          <category>apache</category>
                  <category>configuration</category>
                  <category>https</category>
                  <category>server</category>
                <description>          &lt;p&gt;You want to configure &amp;#8220;once and for all&amp;#8221; HTTPs for all domains and sub-domains handled by your webserver, and you don&amp;#8217;t want to redeclare the certificate in each VirtualHost. Here is the trick.&lt;/p&gt;
&lt;p&gt;I run Debian. In a default Apache installation, the directory &lt;strong&gt;/etc/sites-enabled&lt;/strong&gt; contains a file named &lt;strong&gt;000-default&lt;/strong&gt; which declares a default VirtualHost for HTTP.&lt;/p&gt;
&lt;p&gt;You have to know that when Apache loads an entire directory of configuration files, the files are read in alphabetical order. So if you want to declare something before something else, you can cheat on its name in the loaded configuration. It is exactly what &lt;strong&gt;000-default&lt;/strong&gt; does.&lt;/p&gt;
&lt;p&gt;In &lt;strong&gt;/etc/apache2/sites-available&lt;/strong&gt;, you have a file named &lt;strong&gt;default-ssl&lt;/strong&gt;. Edit this file to fit your needs (path to certificate, etc). Note that this certificate will be the same for all the domains hosted on your server. It&amp;#8217;s what we want&amp;#160;: only one configuration. If you are hosting multiple domains on the same server, the certificate will probably be invalid for at least one of your domains, and you should use &lt;a hreflang=&quot;en&quot; href=&quot;http://httpd.apache.org/docs/trunk/en/mod/mod_macro.html&quot;&gt;mod_macro&lt;/a&gt; instead of a global HTTPs configuration.&lt;/p&gt;
&lt;p&gt;Now, enable the website the common way&amp;#160;: &lt;strong&gt;a2ensite default-ssl&lt;/strong&gt;. Don&amp;#8217;t restart Apache yet.&lt;/p&gt;
&lt;p&gt;Rename the file &lt;strong&gt;default-ssl&lt;/strong&gt; created in &lt;strong&gt;/etc/apache2/sites-enabled/&lt;/strong&gt; to &lt;strong&gt;000-default-ssl&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Configure your other VirtualHost with a &lt;strong&gt;*:80&lt;/strong&gt; section and a &lt;strong&gt;*:443&lt;/strong&gt; section, as usual but without specifying certificate and SSL informations for VirtualHosts on &lt;strong&gt;*:443&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;If you restart Apache, you will notice something like this&amp;#160;:&lt;/p&gt;
&lt;pre&gt;_default_ virtualhost overlap on port 443&lt;/pre&gt;
&lt;p&gt;To get rid of these warnings, just add to your &lt;strong&gt;ports.conf&lt;/strong&gt;, in the right section&amp;#160;: &lt;/p&gt;
&lt;pre&gt;NameVirtualHost *:443
Listen 443 http&lt;/pre&gt;
&lt;p&gt;When you finally restart Apache, every VirtualHost declared as &lt;strong&gt;*:443&lt;/strong&gt; will use the certificate defined in &lt;strong&gt;000-default-ssl&lt;/strong&gt; without mentioning it.&lt;/p&gt;</description>
        
              </item>
      </channel>
</rss>
