Forum Discussion
chris_16019
Nimbostratus
May 29, 2008Basic SSL Profile question
Please forgive the noobish question, I've only just returned fromt the basic LTM training.
I have two secure certificates and keys that need applying to an SSL profile, and then to a virtual server. However, I only appear to be able to apply one certificate to a profile, and one profile to a virtual server.
If you have two HTTPS:// websites behind one virtual server how do you apply two certificates to one SSL profile or apply two profiles to one virtual server?
Thanks in advance.
- hoolio
Cirrostratus
Hi, - chris_16019
Nimbostratus
Hi Aaron, thanks for the response. - hoolio
Cirrostratus
The issue isn't with BIG-IP--it's with HTTPS as a protocol. When a client makes an HTTPS request, the HTTP host header value is encrypted. In order to present the correct certificate you must know which Host (abc.pl or abc.com.pl) the client has made the request to. In order to see the host header value, you must decrypt the SSL. To do so, you have to present a certificate to the client. You're right that this comes up frequently--unfortunately, the solution isn't an iRule, it's using separate virtual servers or a single certificate which is valid for multiple FQDN's. - chris_16019
Nimbostratus
Excellent - thanks for the detailed responses. I'll look into what you have suggested.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects