Forum Discussion
KenJ_50171
Nimbostratus
Jul 21, 2009certificate for serverssl
I'm grappling with what it means to have a certificate for a "serverssl" profile, between the F5 Big-IP LTM and the back-end server. (I have a paranoid application owner who wants to do this, and it...
hoolio
Cirrostratus
Jul 21, 2009Sorry, maybe I misinterpreted what the poster was trying to do.
"I have a paranoid application owner who wants to do this, and it's a low-traffic service so bandwidth and CPU are not an issue."
Ken, did you mean you wanted to use client/server certs for the server side connection or just server SSL without a client cert on LTM? If the latter, as Denny says, you can just use the default server SSL profile. LTM won't send a client cert and won't do any checking of the server's certificate. If you want/need to, you could configure the Trusted Certificate Authorities, Chain and Server Certificate to validate the client cert. All you would be doing though is ensuring LTM and the server are only connecting to each other--you wouldn't be checking anything to do with the clientside certificates/identity.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
