Forum Discussion
2 way SSL implementation
Hi All,
We are currently implementing 2-way SSL on our F5. Servers is using port 8011 and we need to encrypt only from client to F5. Now, we use self-signed certificate from F5 since the client don't want to spend money on signing certificates to CA. We can access the application via https but CLIENT wants client authentication to be enabled because when we access the application, wether the ssl certificate is installed on browser or not, we can still access the application.
Thanks! Ferdz
30 Replies
- Kevin_Stewart
Employee
Yes. This one self-signed certificate would need to be installed on the client, in the client SSL certificate and key, and Trusted Certificate Authorities section.
- Spidey_29396
Nimbostratus
So it will look like this one?
- Spidey_29396
Nimbostratus
So it will look like this one?
- Kevin_Stewart
Employee
That looks about right, but two questions:
-
Why Frequency of always?
-
Do you need pass phrase?
-
- Spidey_29396
Nimbostratus
- client wants to have authentication set to always
- nope.can i remove the pass phrase?
- Kevin_Stewart
Employee
If the client understands what that setting means then that's fine. Otherwise it adds overhead. The pass phrase is NOT necessary. Have you tested with the new configuration?
- Spidey_29396
Nimbostratus
Hi Kevin,
not yet, Im currently doing a workplan for our client. I need to simulate this further in the lab. I'll let you know the result once implemented by our client.
Thanks! Ferdz
- Spidey_29396
Nimbostratus
Hi Kevin,
The testing was successsful in lab using only ip address(https://10.10.10.10) but unsuccessful in production because the VIP in production is redirecting i.e. https://10.10.10.10 to https://10.10.10.10/ordering?WDSL this is the behavior of their application(ESB). it says "the connection is interrupted". Are we missing something on the config?
- Kevin_Stewart
Employee
If you're redirecting to a different URI on the same host, the problem is most likely NOT SSL - if for no other reason than you are actually seeing the layer 7 (HTTP) payload to do the redirect (which wouldn't be possible if SSL was failing). Do you actually see an HTTP redirect at the client? Can you get a more detailed capture and share that?
- Spidey_29396
Nimbostratus
Sorry for the confusion kevin,actually they are accessing the application using the url https://10.10.10.10/ordering?WDSL.it is working with http but when we use ssl and the config you had suggested,it say "connection interrupted"
- Spidey_29396
Nimbostratus
Sorry for the confusion kevin,actually they are accessing the application using the url https://10.10.10.10/ordering?WDSL.it is working with http but when we use ssl and the config you had suggested,it say "connection interrupted"
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com