For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

cylinh_171509's avatar
cylinh_171509
Icon for Altocumulus rankAltocumulus
Nov 06, 2015

1 VIP 3 URL 3SSL Certs all on port 443 is it possible?

all,

 

i need help, i have a scenerior...

 

1 VIP 3 URL 3 Cert all on tcp port 443. how do i get the certs to allighn with the different URL? i read up on the SNI and makes sence but i have 3 different name so im still confused. Is it possible with my scenerio at all?

 

Thanks..and appreciate all reply.

 

3 Replies

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    SNI basically entails creating a Client SSL profile per hostname, perhaps, which has 3 different certificates. You can then apply the three client SSL profiles to the Virtual Server configuration. If a client supports SNI then the first part of the communication will be to discover the hostname and associated client ssl profile. once this is done the ssl handshake can continue as normal.

     

    By the way, you will need to configure one client SSL profile to be the default one (in the profile itself), just in case hostnames don't match the certificates. I believe you also need to enter in the hostname into the Server Name field too. Again in the client ssl profile.

     

    See sol13452

     

    Hope this helps,

     

    N

     

  • Thanks for the quick reply, this has fixed my problem. Was my lack of understanding on base sslprofile