I have a reverse proxy handling ssl termination and mod_security. The issue is after sso reaches the backend server it tries to authenticate with cas directly instead of the through the proxy still, and since the backend server is inside our firewall, and only the proxy is in cas the authentication fails.

current configuration for reverse proxy:

  <Location /test/>
   ProxyPreserveHost on
   RequestHeader set WL-Proxy-SSL true
   ProxyPass /TEST/ http://backend.server.com:7010/
   ProxyPassReverse http://backend.server.com:7010/
   ProxyHTMLURLMap http://backend.server.com:7010

   Order allow,deny
   Allow from all

  <Location /sso/>
   ProxyPreserveHost on
   RequestHeader set WL-Proxy-SSL true
   ProxyPass http://backend.server.com:7007/sso/
  ProxyPassReverse http://backend.server.com:7007/sso/
  ProxyHTMLURLMap http://backend.server.com.edu:7007/sso
  Order allow,deny
  Allow from all

It there some setting i am missing that causes the backend server to not continue with using the proxy name?

1 Answers1


Most applications I've seen that support being behind a load balancer or reverse proxy have a setting such as "base URL" that you can set to the front end's URL. This allows the application to create the proper hyperlinks in itself and things like mail notifications.

Ryan Bolger
  • 16,472
  • 3
  • 40
  • 59
  • The issue was with the backend server. There was a specific module that needed to be loaded for the weblogic server to understand and properly use the frontend server. Was a change between versions i was unaware of. – Rory McDonald Jun 15 '15 at 21:20