The CA connectors of Identity Manager use a session ID cookie embedded in the cardjob to allow the JPKIEncoder to authenticate any CA requests it has to make. The reverse proxy's authentication layer must allow the CA connector cookies without authentication. Calls will still be authenticated, via Identity Manager itself.
Enable everything in the /ws/ca_connectors/ folder to pass through without authentication. For example:
https://prime.with.hag/prime_explorer/ws/ca_connectors/*
=>
https://prime.internal:8443/prime_explorer/ws/ca_connectors/*