server { listen 443 ssl; listen [::]:443 ssl; server_name offsite-ejbca.mracs.dev; large_client_header_buffers 4 16k; location / { allow 63.141.252.133; deny all; proxy_pass https://localhost:7563; proxy_set_header X-SSL-CERT $http_x_ssl_cert; proxy_set_header X-Client-Verify $http_x_client_verify; proxy_set_header X-Client-DN $http_x_client_dn; proxy_set_header X-Client-Serial $http_x_client_serial; } location /test-headers { return 200 "X-SSL-CERT: $http_x_ssl_cert\nX-Client-Verify: $http_x_client_verify\nX-Client-DN: $http_x_client_dn\nX-Client-Serial: $http_x_client_serial\n"; add_header Content-Type text/plain; } }