Forum Discussion
Bundle Certificate
In short, using SNI it is possible to use multiple wildcard certs on one VIP. You must configure each client SSL profile accordingly:
- The wildcard cert and key
- The Server Name attribute must match the cert common name (ex. *.domain.com)
- In one of the profiles you must select the "Default SSL Profile for SNI"
Add both client SSL profiles to the VIP.
You cannot use a bundle cert in this instance, because you need a mechanism like SNI to be able to switch between the certs based on the client request. The one big caveat with SNI is that it's only supported by clients that support TLS. That's not so much an issue these days, but anyone running Windows XP and IE6 (and below) will have problems.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com