# Login\_check SSL issue with Reverse Proxy

**URL:** <https://forum.mautic.org/t/login-check-ssl-issue-with-reverse-proxy/36672>\
**Category:** Mautic 6 Install/Upgrade Support\
**Created:** [October 3, 2025, 10:24pm UTC](https://forum.mautic.org/t/login-check-ssl-issue-with-reverse-proxy/36672 "2025-10-03T22:24:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![corytetraprime](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/corytetraprime/32/12676_2.png) [@corytetraprime](https://forum.mautic.org/u/corytetraprime)\
**Post date:** [October 3, 2025, 10:24pm UTC](https://forum.mautic.org/t/login-check-ssl-issue-with-reverse-proxy/36672/1 "2025-10-03T22:24:01Z")

</div>

Greetings and thank you for any assistance! I’ll keep the details to the concise info but please feel free to ask any deeper questions.

Architecture

1. Hyper-V virtual machines running on a Windows 11 host.
2. All VMs are Ubuntu 22 or 24 servers
3. VM 1 is a reverse proxy server that’s handling the SSL and traffic routing to the Mautic VMs.
4. VM 2 is a functioning Mautic 5 instance serving on port 80 but passing traffic securely back through to the VM1 reverse proxy server.

New Mautic 6 VM

1. I setup a new VM and got Mautic 6 configured in the same way I did the previous instance.
2. I’m able to load the new Mautic 6 in browser, over SSL, on the public domain.
3. I’m able to get through the installer and to the login page on a valid SSL connection with cert.
4. On attempted login, the /login\_check path first gets hit insecurely on HTTP and login-loops right back to the Login page.

Solutions I’ve tried

1. My site URL is correct in the Mautic config file

2. Proxy and SSL mods are on

3. I have trusted\_hosts and truested\_proxies set to the proper domains and IPs.

4. Added SSL directives to my Mautic 6 VM virtualhost 80 and are pointing at the proper IP for the reverse proxy server. For example:

I think that’s about all I’ve got. I’ve probably tried some other minor things because I was at it for a few hours. Thank you again! 🙂

---

<div class="post-metadata">

**Author:** ![corytetraprime](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/corytetraprime/32/12676_2.png) [@corytetraprime](https://forum.mautic.org/u/corytetraprime)\
**Post date:** [October 4, 2025, 2:22pm UTC](https://forum.mautic.org/t/login-check-ssl-issue-with-reverse-proxy/36672/2 "2025-10-04T14:22:00Z")

</div>

> [@corytetraprime](#):
>
> `RequestHeader set X-Forwarded-Proto "http"`

Typo, this is actually: RequestHeader set X-Forwarded-Proto “https”
