# Shopware 6 mit SSL hinter Reverse-Proxy

**URL:** <https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571>\
**Category:** Administration\
**Created:** [5. September 2019 um 15:07 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571 "2019-09-05T15:07:36Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![marfie](https://avatars.discourse-cdn.com/v4/letter/m/3e96dc/32.png) [@marfie](https://forum.shopware.com/u/marfie)\
**Post date:** [5. September 2019 um 15:07 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/1 "2019-09-05T15:07:36Z")

</div>

Shopware läuft bei mir hinter einem Nginx. Zwischen Client und NGINX gibt es eine SSL verschlüsselung, zwischen NGINX und Shopware nicht.

Das Laden vom Admin-Bereich scheitert jetzt an Mixed-Content-Fehlern:  
app.js?1567695499:29 Mixed Content: The page at ‘[https://xxxxxxxxxxxx.com/admin#/](https://xxxxxxxxxxxx.com/admin#/)’ was loaded over HTTPS, but requested an insecure XMLHttpRequest endpoint ‘[http://xxxxxxxxxxxx.com/api/v1/\_info/open-api-schema.json](http://xxxxxxxxxxxx.com/api/v1/_info/open-api-schema.json)’. This request has been blocked; the content must be served over HTTPS.

Ich konnte keine Dokumentation finden, wie ich ihn richtig konfiguriere. Lande immer wieder bei der Shopware 5 Dokumentation.

Gibt es schon eine Dokumentation? Oder gibt es einen Tipp, wo ich das konfigurieren kann?

Die Instanz ist unter [https://xxxxxxxxxxxx.com](https://xxxxxxxxxxxx.com) frisch installiert worden. Die Installation lief fehlerfrei durch.

Viele Grüße,

Markus

---

<div class="post-metadata">

**Author:** ![Moritz\_Naczenski](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/moritz_naczenski/32/7792_2.png) [@Moritz\_Naczenski](https://forum.shopware.com/u/Moritz_Naczenski)\
**Post date:** [5. September 2019 um 15:10 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/2 "2019-09-05T15:10:52Z")

</div>

Shopware 6 ist ja eine Symfony Applikation, entsprechend ist da auch nichts Shopware spezifisches notwendig.

&nbsp;

[https://symfony.com/doc/current/deployment/proxies.html](https://symfony.com/doc/current/deployment/proxies.html)

Die TrustedProxies kannst du via environment definieren.

[https://github.com/shopware/development/blob/master/public/index.php#L30](https://github.com/shopware/development/blob/master/public/index.php#L30)

&nbsp;

---

<div class="post-metadata">

**Author:** ![anon2744023](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@anon2744023](https://forum.shopware.com/u/anon2744023)\
**Post date:** [27. November 2019 um 10:16 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/3 "2019-11-27T10:16:42Z")

</div>

Hallo Moritz,&nbsp;

> [@Moritz Naczenski schrieb:](https://forum.shopware.com/profile/14574/Moritz%20Naczenski "Moritz%20Naczenski")
> 
> Shopware 6 ist ja eine Symfony Applikation, entsprechend ist da auch nichts Shopware spezifisches notwendig.
> 
> &nbsp;
> 
> [https://symfony.com/doc/current/deployment/proxies.html](https://symfony.com/doc/current/deployment/proxies.html)
> 
> Die TrustedProxies kannst du via environment definieren.
> 
> [https://github.com/shopware/development/blob/master/public/index.php#L30](https://github.com/shopware/development/blob/master/public/index.php#L30)
> 
> &nbsp;

ich habe genau das gleiche Problem. Ich nutze einen Amazon AWS EC2-Server mit einem Load Balancer, der die SSL-Verschlüsselung ermöglicht. Wie muss ich vorgehen, dass ich mich auch wieder in das Adminmenü einlogen kann und dass das Problem mit dem „Mixed Content“ behoben wird?

Vielen Dank für deine Unterstützung und deine Rückmeldung.

Viele Grüße  
Stefan Börner&nbsp;&nbsp;

---

<div class="post-metadata">

**Author:** ![Moritz\_Naczenski](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/moritz_naczenski/32/7792_2.png) [@Moritz\_Naczenski](https://forum.shopware.com/u/Moritz_Naczenski)\
**Post date:** [27. November 2019 um 10:21 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/4 "2019-11-27T10:21:05Z")

</div>

Aber das steht ja in den verlinkten Artikeln?  
&nbsp;

---

<div class="post-metadata">

**Author:** ![anon2744023](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@anon2744023](https://forum.shopware.com/u/anon2744023)\
**Post date:** [27. November 2019 um 10:39 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/5 "2019-11-27T10:39:06Z")

</div>

Hallo Herr Naczenski,&nbsp;

> [@Moritz Naczenski schrieb:](https://forum.shopware.com/profile/14574/Moritz%20Naczenski "Moritz%20Naczenski")
> 
> Aber das steht ja in den verlinkten Artikeln?  
> &nbsp;

danke für Ihre schnelle Rückmeldung. Ich habe grundsätzliche Fragen:

1. Wo installiere ich Symfony? Auf meinem Webserver, wo auch die Shopware-Installation liegt?
2. Starte ich Symfony nach der Installation und muss Eingaben machen, wie hier beschrieben? ([https://symfony.com/doc/current/deployment/proxies.html](https://symfony.com/doc/current/deployment/proxies.html))

Vielen Dank für Ihre Rückmeldung.

Viele Grüße  
Stefan Börner

---

<div class="post-metadata">

**Author:** ![sonic](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/sonic/32/25728_2.png) [@sonic](https://forum.shopware.com/u/sonic)\
**Post date:** [27. November 2019 um 10:41 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/6 "2019-11-27T10:41:50Z")

</div>

Ich glaube, wer DIESE Frage stellt, sollte tunlichst die Finger vom „Selber Hosten“ lassen, und eine Person beauftragen, die wenigstens ein paar grundlegende Basics beherrscht.  
Symfony ist ein PHP-Framework, welches zusammen mit SW6 bereits installiert und immer mit ausgeführt wird.

---

<div class="post-metadata">

**Author:** ![Moritz\_Naczenski](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/moritz_naczenski/32/7792_2.png) [@Moritz\_Naczenski](https://forum.shopware.com/u/Moritz_Naczenski)\
**Post date:** [27. November 2019 um 10:55 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/7 "2019-11-27T10:55:05Z")

</div>

Der Bertrieb eines Load-Balancers bedingt schon ein gewisses Know-How im Hosting-Bereich, gerade auch was die Eirichtung angeht.

Shopware basiert auf Symfony - man muss also nichts installieren, sondern nur die Umgebungsvariablen deines Servers entsprechend konfigurieren. Symfony prüft hier auf folgende Variablen:

$\_SERVER[‘TRUSTED\_PROXIES’]&nbsp;

$\_ENV[‘TRUSTED\_PROXIES’]

Diese sollten die IPs des Proxies beinhalten

---

<div class="post-metadata">

**Author:** ![anon2744023](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@anon2744023](https://forum.shopware.com/u/anon2744023)\
**Post date:** [27. November 2019 um 11:44 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/8 "2019-11-27T11:44:56Z")

</div>

Hallo Herr Naczenski,&nbsp;

> [@Moritz Naczenski schrieb:](https://forum.shopware.com/profile/14574/Moritz%20Naczenski "Moritz%20Naczenski")
> 
> Der Bertrieb eines Load-Balancers bedingt schon ein gewisses Know-How im Hosting-Bereich, gerade auch was die Eirichtung angeht.
> 
> Shopware basiert auf Symfony - man muss also nichts installieren, sondern nur die Umgebungsvariablen deines Servers entsprechend konfigurieren. Symfony prüft hier auf folgende Variablen:
> 
> $\_SERVER[‚TRUSTED\_PROXIES‘]&nbsp;
> 
> $\_ENV[‚TRUSTED\_PROXIES‘]
> 
> Diese sollten die IPs des Proxies beinhalten

vielen Dank für Ihre Rückmeldung. Können Sie mir sagen, in welcher Datei ich die Variablen&nbsp;&nbsp;

$\_SERVER[‚TRUSTED\_PROXIES‘]&nbsp;

$\_ENV[‚TRUSTED\_PROXIES‘]

anpassen muss?

Viele Grüße  
Stefan Börner

---

<div class="post-metadata">

**Author:** ![wwb-3s](https://avatars.discourse-cdn.com/v4/letter/w/f0a364/32.png) [@wwb-3s](https://forum.shopware.com/u/wwb-3s)\
**Post date:** [27. Mai 2022 um 11:59 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/9 "2022-05-27T11:59:59Z")

</div>

Hallo, mir ist nicht ganz klar, was genau auf github „erklärt“ worden sein soll, alles was ich da sehe ist eine index.php.

Heißt dass, man muss die eigene index.php um den trusted proxy part erweitern?? Ein wenig mehr Information dazu wären hilfreich.

Der Link zu symfony ist leider auch nicht viel aufschlussreicher. Wenn ich das korrekt verstehe, soll man unter config/packages die framework datei anpassen um die als YAML / XML oder PHP angeben, wobei man dort seine eigenen Angaben wie IP Adresse einfügt.

Ist das richtig?

---

<div class="post-metadata">

**Author:** ![discordier](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/discordier/32/21282_2.png) [@discordier](https://forum.shopware.com/u/discordier)\
**Post date:** [14. Juli 2023 um 13:20 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/10 "2023-07-14T13:20:35Z")

</div>

Da das Thema auch in 6.5 noch Relevanz hat und ich einen Lösungsvorschlag eingereicht habe, möge man mir das Necroposting verzeihen.

In der index.php steht welche Environment Variablen du setzen kannst, hiermit kannst du alles bis auf ``.

Der Weg via framework.yaml funktioniert leider aktuell noch nicht. Ich habe hierzu einen PR auf GitHub gestellt:

> <https://github.com/shopware/platform/pull/3217>
>
> The code for handling the kernel parameters \`trusted\_\*\` has been omitted in \`\\Sh…opware\\Core\\Kernel::boot()\`.
> 
> This rendered the normal way of configuring these parameters in a Symfony application useless.
> 
> \### 1. Why is this change necessary?
> 
> The method \`\\Shopware\\Core\\Kernel::boot()\` \[is missing\](https://github.com/shopware/platform/blob/fb06e27d30b8f34953dff30dc556d44fc428e235/src/Core/Kernel.php#L168) the \[handling of \`trusted\_\*\` parameters\](https://github.com/symfony/symfony/blob/e15ccda3d5e05c152310127130d23239ee763de0/src/Symfony/Component/HttpKernel/Kernel.php#L759) that are implemented in the upstream Symfony kernel.
> 
> \### 2. What does this change do, exactly?
> 
> This change implements handling of said parameters.
> 
> However, as upstream implements them in the private method \`preBoot()\`, I have implemented them in the calling method \`boot()\` instead.
> 
> \### 3. Describe each step to reproduce the issue or behaviour.
> 
> Create a framework bundle configuration as mentioned in the official Symfony docs \[here\](https://symfony.com/doc/6.2/deployment/proxies.html#solution-settrustedproxies) and suggested in Shopware community by Moritz Naczenski \[here\](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/2).
> 
> \### 4. Please link to the relevant issues (if any).
> 
> Don't know of any issue.
> 
> \### 5. Checklist
> 
> \- \[X\] I have rebased my changes to remove merge conflicts
> \- \[\] I have written tests and verified that they fail without my change
> - I failed to locate any tests that are related to the kernel specifically - pointers welcome. 
> \- \[X\] I have created a \[changelog file\](https://github.com/shopware/platform/blob/trunk/adr/2020-08-03-implement-new-changelog.md) with all necessary information about my changes
> \- \[\] I have written or adjusted the documentation according to my changes
> \- \[\] This change has comments for package types, values, functions, and non-obvious lines of code
> \- \[X\] I have read the contribution requirements and fulfil them.
> 
> \<!--
> copilot:summary
> \--\>
> \### \<samp\>🤖 Generated by Copilot at b4bd51e\</samp\>
> 
> This pull request improves the security and compatibility of the Shopware kernel with Symfony by setting the trusted proxies and headers from the configuration. It affects the file \`src/Core/Kernel.php\` and adds a changelog entry in \`changelog/\_unreleased/2023-07-14-trusted-kernel-parameters.md\`.
> 
> \<!--
> copilot:walkthrough
> \--\>
> \### \<samp\>🤖 Generated by Copilot at b4bd51e\</samp\>
> 
> \* Add a changelog entry for the fix (\[link\](https://github.com/shopware/platform/pull/3217/files?diff=unified&w=0#diff-0736b50ed25cfc62d2637a922d88e2de80a82a06472ae8d65844f76a5bde87e3R1-R8))
> \* Import the \`Request\` class from Symfony in the \`Kernel\` class (\[link\](https://github.com/shopware/platform/pull/3217/files?diff=unified&w=0#diff-0f9fbc724c97e5f417094a9615b21a5aef470b2b2086c24ec21e4dc7cdfa5fe3R16))
> \* Set the trusted hosts, proxies, and headers from the kernel parameters to the \`Request\` class in the \`Kernel::boot\` method (\[link\](https://github.com/shopware/platform/pull/3217/files?diff=unified&w=0#diff-0f9fbc724c97e5f417094a9615b21a5aef470b2b2086c24ec21e4dc7cdfa5fe3R169-R179))

> **[Shopware Issuetracker](https://issues.shopware.com/issues/NEXT-29302)**
>
> Shopware Issuetracker

---

<div class="post-metadata">

**Author:** ![nets](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@nets](https://forum.shopware.com/u/nets)\
**Post date:** [24. April 2024 um 09:32 UTC](https://forum.shopware.com/t/shopware-6-mit-ssl-hinter-reverse-proxy/61571/11 "2024-04-24T09:32:30Z")

</div>

Danke, discordier, die index.php hier hat mir geholfen, weder die /www/.env noch die /www/config/packages/framework.yaml haben mir geholfen… ENDLICH
