# Change upstream proxy for https flow

**URL:** <https://discourse.mitmproxy.org/t/change-upstream-proxy-for-https-flow/347>\
**Category:** help\
**Created:** [February 8, 2017, 8:05am UTC](https://discourse.mitmproxy.org/t/change-upstream-proxy-for-https-flow/347 "2017-02-08T08:05:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![wmrowan](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/wmrowan/32/112_2.png) [@wmrowan](https://discourse.mitmproxy.org/u/wmrowan)\
**Post date:** [February 8, 2017, 8:05am UTC](https://discourse.mitmproxy.org/t/change-upstream-proxy-for-https-flow/347/1 "2017-02-08T08:05:58Z")

</div>

My eventual goal is to dynamically change the upstream proxy of my https flow based on the domain of the destination server or the value of a header.

For now, I’m just trying to get a minimal example working following the example of [https://github.com/mitmproxy/mitmproxy/blob/master/examples/complex/change\_upstream\_proxy.py](https://github.com/mitmproxy/mitmproxy/blob/master/examples/complex/change_upstream_proxy.py) but I’m not getting the expected results.

I run `mitmdump` in upstream mode like so:

```bash
mitmdump -U https://default-proxy:port -s change-upstream.py

```

With this script

```python
def request(flow):
  flow.live.change_upstream_proxy_server(("other-proxy", port))

```

When make an http request through mitm to an ip echo server I get the ip of “other-proxy” as expected.

```bash
curl -x localhost:8080 http://api.ipify.org --insecure

```

But when I make ah https request instead I get the ip of “default-proxy” indicating that the upstream server of the request was not changed dynamically by the script.

```bash
curl -x localhost:8080 http://api.ipify.org --insecure

```

Mitm proxy logs the request and does not indicate any errors.

```auto
127.0.0.1:34124: clientconnect
127.0.0.1:34124: GET https://api.ipify.org/
              << 200 OK 13b
127.0.0.1:34124: clientdisconnect

```

What do I need to do differently to change the upstream proxy of the https request?

---

<div class="post-metadata">

**Author:** ![PranavPrakash52](https://avatars.discourse-cdn.com/v4/letter/p/91b2a8/32.png) [@PranavPrakash52](https://discourse.mitmproxy.org/u/PranavPrakash52)\
**Post date:** [February 21, 2017, 11:57am UTC](https://discourse.mitmproxy.org/t/change-upstream-proxy-for-https-flow/347/2 "2017-02-21T11:57:23Z")

</div>

In the case of an http request the header and the hostname are visible .But in the case of an https request you wont be able to access the header or hostname .The headers are available only after the TLS handshake occurs.You can change your upstream server after the TLS handshake by using the serverconnect event .

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [February 21, 2017, 1:53pm UTC](https://discourse.mitmproxy.org/t/change-upstream-proxy-for-https-flow/347/3 "2017-02-21T13:53:37Z")

</div>

> What do I need to do differently to change the upstream proxy of the https request?

Sorry for the late reply. We lately fixed a bug regarding that, the next release should have you covered.

---

<div class="post-metadata">

**Author:** ![wmrowan](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/wmrowan/32/112_2.png) [@wmrowan](https://discourse.mitmproxy.org/u/wmrowan)\
**Post date:** [February 24, 2017, 6:36am UTC](https://discourse.mitmproxy.org/t/change-upstream-proxy-for-https-flow/347/4 "2017-02-24T06:36:29Z")

</div>

@mhils I just ran this test again after downloading the 2.0 release and it now works as expected. Thanks for the solution.

---

<div class="post-metadata">

**Author:** ![Jake232](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/jake232/32/152_2.png) [@Jake232](https://discourse.mitmproxy.org/u/Jake232)\
**Post date:** [April 21, 2017, 2:27am UTC](https://discourse.mitmproxy.org/t/change-upstream-proxy-for-https-flow/347/5 "2017-04-21T02:27:28Z")

</div>

@wmrowan You got this working? I am using the latest version but it seems HTTPS still uses the default proxy. As described here:

> [@Upstream Proxy HTTPS](https://discourse.mitmproxy.org/t/upstream-proxy-https/452):
>
> I have my script changing the upstream proxy for HTTP connections, but it seems to fail for HTTPS connections. Here’s a basic stripped down example. The script works fine for [http://api.ipify.org/](http://api.ipify.org/), but fails for [https://api.ipify.org/](https://api.ipify.org/). With HTTPS I see the following, which shows the upstream proxy wasn’t changed. Server connection to default\_proxy:8888 failed: Error connecting to "default\_proxy": [Errno 8] nodename nor servname provided, or not known Running Command: mitmdump -s utilities/…

Got any insight?

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [April 21, 2017, 2:41pm UTC](https://discourse.mitmproxy.org/t/change-upstream-proxy-for-https-flow/347/6 "2017-04-21T14:41:48Z")

</div>

@Jake232: See [https://github.com/mitmproxy/mitmproxy/issues/2253](https://github.com/mitmproxy/mitmproxy/issues/2253)
