# You're speaking plain HTTP to an SSL-enabled server port.

**URL:** <https://discuss.kubernetes.io/t/youre-speaking-plain-http-to-an-ssl-enabled-server-port/10051>\
**Category:** General Discussions\
**Created:** [March 12, 2020, 6:57pm UTC](https://discuss.kubernetes.io/t/youre-speaking-plain-http-to-an-ssl-enabled-server-port/10051 "2020-03-12T18:57:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shahid\_Mushtaq](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/shahid_mushtaq/32/4424_2.png) [@Shahid\_Mushtaq](https://discuss.kubernetes.io/u/Shahid_Mushtaq)\
**Post date:** [March 12, 2020, 6:57pm UTC](https://discuss.kubernetes.io/t/youre-speaking-plain-http-to-an-ssl-enabled-server-port/10051/1 "2020-03-12T18:57:40Z")

</div>

My Gateway file is asapiVersion: [networking.istio.io/v1alpha3](https://slack-redir.net/link?url=http%3A%2F%2Fnetworking.istio.io%2Fv1alpha3)  
kind: Gateway  
metadata:  
name: my-gateway-secure  
namespace: myapp  
spec:  
selector:  
istio: ingressgateway # use istio default controller  
servers:

- port:  
number: 443  
name: https  
protocol: HTTPS  
tls:  
mode: SIMPLE  
serverCertificate: /etc/istio/ingressgateway-certs/tls.crt  
privateKey: /etc/istio/ingressgateway-certs/tls.key  
#caCertificates: /etc/istio/ingressgateway-ca-certs/kbundle.crt  
hosts:
- “\*”  
—apiVersion: [networking.istio.io/v1alpha3](https://slack-redir.net/link?url=http%3A%2F%2Fnetworking.istio.io%2Fv1alpha3)  
kind: VirtualService  
metadata:  
name: my-gateway-service-secure  
namespace:myapp  
spec:  
hosts:
- “[sub.domaincom](https://slack-redir.net/link?url=http%3A%2F%2Fsub.domain..com)”  
gateways:
- my-gateway-secure  
http:
- route:
- destination:  
host: my-mono  
port:  
number: 443  
protocol: TCPand my service file isapiVersion: v1  
kind: Service  
metadata:  
name: my-mono  
namespace: myapp  
labels:  
tier: backend  
spec:  
selector:  
app: my-mono  
tier: backend  
ports:
- port: 443  
name: https  
protocol: TCP

when i access my service using gateway it saysBad Request  
Your browser sent a request that this server could not understand.  
Reason: You’re speaking plain HTTP to an SSL-enabled server port.  
Instead use the HTTPS scheme to access this URL, please.Apache/2.4.38 (Debian) Server at 10.0.159.77 Port 443i can confirm that apache is only listening on 443 and is properly configured. can someone help me with it. Thanks

---

<div class="post-metadata">

**Author:** ![stephendotcarter](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/stephendotcarter/32/4528_2.png) [@stephendotcarter](https://discuss.kubernetes.io/u/stephendotcarter)\
**Post date:** [March 12, 2020, 7:33pm UTC](https://discuss.kubernetes.io/t/youre-speaking-plain-http-to-an-ssl-enabled-server-port/10051/2 "2020-03-12T19:33:50Z")

</div>

I think Istio is decrypting the HTTPS connection and sending plain HTTP to your application.

I think you need to make your application listing on port 80 or else configure Istio to make a HTTPS connection to your app.

Kind regards,  
Stephen

---

<div class="post-metadata">

**Author:** ![Shahid\_Mushtaq](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/shahid_mushtaq/32/4424_2.png) [@Shahid\_Mushtaq](https://discuss.kubernetes.io/u/Shahid_Mushtaq)\
**Post date:** [March 13, 2020, 6:34am UTC](https://discuss.kubernetes.io/t/youre-speaking-plain-http-to-an-ssl-enabled-server-port/10051/3 "2020-03-13T06:34:28Z")

</div>

I replaced Simple TLS to Mutual TLS . as Simple TLS was terminating/encrypting header . and it worked. thanks for your help
