Prev Next

Web / NGINX Interview questions

What is SSL termination in NGINX?

SSL termination means NGINX decrypts incoming HTTPS traffic and forwards the request to backend servers as plain HTTP (or re-encrypts it separately). The client-facing connection is encrypted; the internal connection typically isn't, unless the backend also requires TLS.

server {
    listen 443 ssl;
    server_name example.com;
    ssl_certificate /etc/nginx/ssl/example.com.crt;
    ssl_certificate_key /etc/nginx/ssl/example.com.key;

    location / {
        proxy_pass http://backend_app;
    }
}

Centralizing TLS at NGINX means certificates only need to be managed and renewed in one place, and application servers are freed from handling encryption work themselves.

In SSL termination, where does the HTTPS decryption happen?
What is a practical benefit of centralizing TLS at NGINX?

More Related questions...

What is NGINX? What is the purpose of NGINX as a reverse proxy? What are the main features of NGINX? What are the types of context blocks in NGINX configuration? Define upstream in NGINX? What is the master-worker process model in NGINX? List common NGINX configuration directives? How do you install NGINX on Ubuntu? How do you start, stop, and reload NGINX? What is the nginx.conf file? What are server blocks in NGINX? What is a location block in NGINX? How do you serve static files with NGINX? What is load balancing in NGINX? What are the types of load balancing methods in NGINX? Define a virtual host in NGINX? What is SSL termination in NGINX? How do you enable Gzip compression in NGINX? What is caching in NGINX? What is the purpose of the events block in NGINX? What is the difference between NGINX and Apache HTTP Server? What is the difference between proxy_pass and rewrite in NGINX? What is the difference between a forward proxy and a reverse proxy? How does NGINX handle concurrent client connections? How does NGINX's event-driven architecture work? Why is NGINX considered more performant than process-per-connection servers? Why do we use upstream blocks with multiple servers? When should you use NGINX purely as a reverse proxy versus also as a load balancer? When would you choose round robin over least_conn load balancing? What happens when an upstream server fails a health check? How is SSL/TLS termination configured in NGINX? How can you optimize NGINX for high-traffic websites? How do you troubleshoot a 502 Bad Gateway error in NGINX? How do you troubleshoot high memory usage in NGINX worker processes? Explain the lifecycle of an HTTP request in NGINX? Explain the execution flow of NGINX's request processing phases? Explain the internal working of NGINX worker processes and the event loop? Why doesn't NGINX use a thread-per-request model like Apache's prefork MPM? Why should location block matching order matter between regex and prefix matches? What is the difference between try_files and rewrite directives? How does NGINX handle SSL session caching for performance? How can you optimize NGINX buffer settings for large file uploads? What is the difference between active and passive health checks in NGINX? How do you troubleshoot NGINX configuration errors before reloading? Why is the worker_connections directive important for concurrency limits? When should you use NGINX caching instead of a dedicated CDN? What is the difference between limit_req and limit_conn for rate limiting? How does NGINX handle WebSocket proxying? Explain the internal working of NGINX's keepalive connection pooling to upstream servers? Why do we use try_files with a fallback to PHP-FPM in WordPress-style setups?
Show more question and Answers...


Comments & Discussions