Jump to content

Emby behind reverse haproxy on pfSense


Mr.Berzerk

Recommended Posts

Mr.Berzerk

Hey everyone.

I've been running emby for a while, and know I want to get remote access working, but Emby is one of 6 servers, so it is a must to be behind a reverse-proxy.

I got http working, but I can't get Emby to work on https/ssl. I have a certificate setup, but, I get this error in my browser when going https.

R_END_OF_FILE_ERROR

From searching the web, it is common for proxies to give this error, but I can't figure out what I need to change in haproxy to correct it.
Emby is using a letsenecrypt certificate, and is is running remote access through 443.

Any help would be appreciated.

Link to comment
Share on other sites

Quote

Emby is using a letsenecrypt certificate

Hi, what do you mean by this? Typically you would setup the certificate at the reverse proxy level rather than Emby.

Link to comment
Share on other sites

Mr.Berzerk

I have Emby setup on a 18.04 ubuntu server. On that server I have certbot setup to automate certificate renewal, as I have emby setup to use emby.mydomain.com.
The proxy is set to have each server do certificate validation, as there are multiple servers with multiple domains on multiple internal ips, and not every domain is owned by the same company, so they are responsible for their own certificates.

Link to comment
Share on other sites

1 hour ago, Mr.Berzerk said:

Besides, emby requires a path to the certificate, and I can't setup a path to my proxy device.

 

Not if the reverse proxy is handling ssl. 

Link to comment
Share on other sites

Mr.Berzerk

But I can't set it that way, without reconfiguring the entire network.

It is probably better to figure out why I am getting that error.

 

Edited by Mr.Berzerk
Link to comment
Share on other sites

  • 1 year later...
jburman01

@Mr.Berzerk did you ever figure out a fix for this? I am going through the same issue now trying to get remote access for Emby to work behind PFSense and HAProxy

Link to comment
Share on other sites

  • 1 year later...
  • 3 months later...
Mr.Berzerk

Ya, sorry I did figure this out. But not in a typical way. I setup a virtual server that strictly manages the certificates, and I copy them to the emby server every time they renew in the certbot post renew script.

On 7/19/2022 at 3:18 PM, jburman01 said:

@Mr.Berzerk did you ever figure out a fix for this? I am going through the same issue now trying to get remote access for Emby to work behind PFSense and HAProxy

 

  • Thanks 1
Link to comment
Share on other sites

Schleudertrauma

Why don't you let haproxy manage all certs for all of your servers? If you want to secure your traffic from haproxy as the entrypoint to your servers behind it, sure, you can do that.

I think it is not that difficult. My emby server runs behind pfSense and haproxy with some other applications and all is working.

But i am not the heavy network genius, so my settings are not the best for sure. :)

 

 

pfsense and haproxy frontend.jpg

  • Agree 1
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...