Forum Discussion
WaterlooSysAdmi
Cirrus
Feb 14, 2020Big-IP - Client Certificate
Hello, We're currently setting up an API on a Microsoft Service Fabric cluster(see below). Clients will be sending requests to the API with their own client certificate(which are subject to ch...
Angelo_V
Cirrus
Feb 15, 2020The simplest solution would be to remove the http profile and the client certificate, going to perform a simple tcp load balance and change the type of VIP in Performance Layer4.
Then install the certificate (wildcard) on the individual pool members.
in the current configuration you have 2 separate SSL connections.I can't imagine how you could impersonate the client, among other things you don't have the private key related to the client certificate.
Angelo
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects