By: Miguel Foo user 14 Jun 2017 at 11 a.m. CDT

2 Responses
Miguel Foo gravatar
Hey, This is more of an opinion/best practice question as I don't see much in the docs about this (correct me if I'm wrong, pls) My ideal setup: ![ideal](http://i.imgur.com/KaOLcrF.png "ideal") But seeing this thread https://support.gluu.org/other/3878/how-to-configure-gluu-without-https-on-apache/ It sounds like, its not recommended to do `SSL offloading` on the downstream reverse proxy(correct me if I'm wrong) It sounds like the recommended approach is something like: ![recommended](http://i.imgur.com/E4idFDI.png "recommended") reverse proxy in this case can be a load balancer appliance but basically it does SSL offloading

By Mohib Zico staff 14 Jun 2017 at 3:53 p.m. CDT

Mohib Zico gravatar
>> its not recommended to do SSL offloading on the downstream reverse proxy(correct me if I'm wrong) Correct, Gluu Server won't work perfectly with http. >> reverse proxy in this case can be a load balancer appliance but basically it does SSL offloading Yes, you can put reverse proxy infront of your SP. However, I would always suggest you to use https everywhere you can ( even in SP ).

By Miguel Foo user 14 Jun 2017 at 5:01 p.m. CDT

Miguel Foo gravatar
For sure, https is always recommend. Thanks that helps