Forum Discussion
Alain_Morin_147
Mar 14, 2014Nimbostratus
Certificates implementation in "SSL forward proxy client and server authentication" scenario.
I want to implement SSL forward proxy client and server authentication, and I am not sure how certificates are implemented. How can it be done? I mean how do I have to implement client and server cer...
Kevin_K_51432
Mar 17, 2014Historic F5 Account
Hi Alain, I would try the steps in the 11.5.0 manual. There is an error in the 11.3.0 manual that has been corrected. This step isn't necessary and has been removed:
Important: The certificate and key that you specify in this profile must match the certificate/key pair that you expect the back-end server to offer. If the back-end server has two or more certificates to offer, you must create a separate Server SSL forward proxy profile for each certificate, and then assign all of the Server SSL forward proxy profiles to a single virtual server.
This was some confusion here with another SSL Proxy feature. Essentially, you should only need the CA key and certificate to sign the newly created (on the fly) certificates.
Corrected guide:
Hope this helps, Kevin
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects