Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
HTTPS is ordinary HTTP sent inside a TLS connection. The browser and the server agree on keys during a handshake, and everything after that is encrypted and protected against tampering. When Traefik serves an HTTPS router, Traefik is the endpoint of that encrypted connection: it decrypts the request, matches a router rule, and forwards the request to a service. Encryption continues past Traefik only if you configure the connection to the service separately.
What HTTPS adds to plain HTTP
Plain HTTP sends requests and responses as readable text. HTTPS runs the same HTTP messages over TLS (Transport Layer Security), a protocol that sits between the transport connection and the application. The TLS 1.3 specification, RFC 8446, states the goal this way:
“TLS allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.”
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
RFC 8446 was published in August 2018. The RFC Editor now marks it obsolete and lists RFC 9846, published in 2026, as its successor. This article explains the handshake using the general TLS 1.3 model and does not describe what changed between the two documents.
#1 Best Overall
In ordinary certificate-based web use, TLS gives you three things. Eavesdroppers cannot read the traffic, tampering is detectable, and the server proves that it holds the private key for the certificate it presents. The certificate ties the connection to the host name the browser asked for.
TLS does not tell you more than that. A padlock means the connection to that server is protected. It does not prove that the business behind the site is legitimate, that the content is accurate, or that the machine at the other end is uncompromised. Also, TLS is not limited to certificates: it defines pre-shared key (PSK) modes as well, so a certificate is not present in every TLS connection.
The TLS 1.3 handshake in the common certificate case
The sequence below describes the full handshake for a browser connecting to a website with a certificate. Handshakes that use a pre-shared key, including resumed sessions, exchange different messages, so treat this as one common pattern rather than a universal rule.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- ClientHello. The browser lists the TLS versions and cipher suites it supports, sends its key-exchange share (its half of the key calculation), and includes the host name it wants in the Server Name Indication (SNI) extension.
- ServerHello. The server selects the parameters it will use and sends its own key share. Both sides can now calculate the same shared secret, and the rest of the handshake is encrypted.
- Server authentication. The server sends its certificate and a signature made with the certificate’s private key over the handshake so far. The browser checks that the certificate chains to a certificate authority it trusts, that it is valid, and that it covers the requested host name.
- Finished messages. Each side sends a Finished message that confirms the handshake was not altered, and both derive the keys that protect application data.
- Application data. HTTP requests and responses travel in TLS records, and each record is protected with authenticated encryption.
Where encryption starts and stops in a Traefik setup
Readers often assume that HTTPS at the front door means the whole path is encrypted. The table shows the hops in a typical Traefik deployment with the default HTTPS router behaviour.
| Hop | Encrypted by default? | What you configure |
|---|---|---|
| Browser to Traefik on an HTTPS router | Yes. Traefik terminates the client-facing TLS connection. | The certificate source (manual or ACME) and TLS options. |
| Traefik to the backend service | Not by default. Traefik sends the decrypted request to the service. | Point the service at an HTTPS URL and set how Traefik verifies it, if your threat model requires encryption on this hop. |
| Browser to Traefik on plain HTTP (port 80, if exposed) | No. The request is sent before any redirect takes effect. | An entrypoint redirect to HTTPS, which only tells the browser where to go next. |
What Traefik does with each connection
The behaviour in this section comes from Traefik’s current official documentation on HTTP TLS, certificates, and entrypoints. Those pages do not tie each default to a specific Traefik release, so confirm defaults such as the fallback certificate against the documentation for the version you run.
1. Accepting the connection on an entrypoint
Traefik listens on entrypoints, which are the network ports it accepts connections on. Entrypoints are often named web for port 80 and websecure for port 443, but the names are your choice. A router must have TLS enabled before Traefik will handle HTTPS for it.
Rank #3
2. Choosing a certificate with SNI
During the handshake, the browser sends the host name it wants in SNI. Traefik uses that name to choose the certificate it presents. This happens before any HTTP request is read, so a router’s Host() rule cannot choose the certificate. If the client sends no SNI, or the name matches no certificate, Traefik falls back to its default certificate, unless strict SNI checking is enabled in the TLS options. With strict checking, the mismatched connection is rejected instead.
Recommended Free Tools
3. Matching the router after decryption
Once the handshake is complete and the request is decrypted, Traefik compares it with the router rules. A rule such as Host(`app.example.com`) selects the router, and the router passes the request to its service. Host matching therefore works on the decrypted request, not on the certificate.
4. Forwarding to the service
Traefik sends the decrypted request to the service the router names. The URL in the service definition sets the protocol on that second leg. If it begins with http://, the connection from Traefik to your application is plain text.
Rank #4
- Each book has 8 sheets (16 pages counting front and back), Sheet Size: 8.5" x 11"
- Each book is produced with smooth 15# white writing paper
- Pages are wide ruled with blue horizontal lines with a red margin
- Proudly made in the USA!
- The covers are a 50# blue offset stapled construction
Getting certificates automatically with ACME
Traefik can obtain and renew certificates through ACME, the automation protocol used by Let’s Encrypt and other certificate authorities. Four things must be in place:
- A certificate resolver defined in the static configuration, which is Traefik’s startup configuration rather than the per-router file.
- TLS enabled on the router that should receive the certificate.
- An ACME challenge type configured on the resolver.
- Domains for the certificate, taken either from the router’s
Host()rules or from explicit domains in the router’s TLS configuration. Explicit domains take precedence when both are present.
A static configuration for a TLS-ALPN challenge looks like this. The email address is a placeholder to replace with your own, and the challenge answers on port 443, so that port must be reachable from the internet.
certificatesResolvers:
letsencrypt:
acme:
email: you@example.com
storage: /letsencrypt/acme.json
tlsChallenge: {}
The router then references the resolver in its TLS block. Here the domain comes from the Host() rule:
Best Value
http:
routers:
app:
rule: "Host(`app.example.com`)"
entryPoints:
- websecure
service: app
tls:
certResolver: letsencrypt
services:
app:
loadBalancer:
servers:
- url: "http://10.0.0.5:8080"
The client-facing connection is HTTPS, while the http:// service URL means the connection from Traefik to the application is not encrypted. Change that URL only after you have confirmed that the application accepts TLS on that port.
Redirecting HTTP to HTTPS
An entrypoint can redirect incoming plain-HTTP requests to HTTPS. The documented default redirect scheme is HTTPS. The following static configuration sends everything arriving on web to the websecure entrypoint:
entryPoints:
web:
address: ":80"
http:
redirections:
entryPoint:
to: websecure
scheme: https
The redirect helps users reach the secure address, but it does not encrypt the original request. The first request, and the redirect response that answers it, travel as plain HTTP. Treat a redirect as a convenience layered on top of HTTPS, not as a substitute for serving HTTPS from the start.
The router TLS trap
Entrypoint TLS settings act as defaults for attached routers, but only when the router has no tls section of its own. A router TLS block replaces the entrypoint settings rather than merging with them. This holds even for an empty block or a block that contains only certResolver.
Suppose the websecure entrypoint enforces a TLS options profile, such as requiring TLS 1.2 or later. If a router adds tls: certResolver: letsencrypt, that router no longer receives the entrypoint profile, and nothing warns you. To keep the expected behaviour, put the required options on the router’s own TLS block alongside the resolver, so each router carries everything it needs.
Quick Recap
Troubleshooting checklist
- The browser shows the wrong certificate or a default certificate. The client sent no SNI, or the name matched no certificate. Confirm the host name in the browser address bar and that a certificate exists for it. If strict SNI checking is off, the default certificate is served without an error on the server side.
- A self-signed certificate appears in production. TLS is enabled on the router, but no real certificate or ACME resolver is attached. Traefik documents a self-signed default certificate for this case and cautions against using it in production.
- No certificate is issued. Check, in order: the resolver is in the static configuration, the router has TLS enabled and references the resolver, the challenge type is configured, and the domains come from a host rule or explicit configuration.
- Router TLS settings seem to be ignored. Look for a router
tlsblock that replaced the entrypoint defaults. Copy the required options onto the router. - The application receives plain HTTP while visitors use HTTPS. This is expected when the service URL uses
http://. It is not a fault in the client-facing TLS connection. - Plain-HTTP requests still reach the application. A redirect only sends the browser to HTTPS. Check that the HTTP entrypoint’s redirect is configured and that the application is not also exposed on plain HTTP through another router.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

