Forum Discussion
spurushothaman_
Nimbostratus
Dec 04, 2015Client Certificate is not passing through back end hosts
I have SSL terminated at F5, we have client certificate for client authentication coming via application request. The client certificate is not passed through the back end systems hence it is reject...
Kevin_Stewart
Employee
Dec 04, 2015Never going to work. This is a fundamental limitation (and security feature) of SSL/TLS. Upon presenting its certificate, a client also presents information signed with its private key. Therefore any device that terminates (and optionally re-encrypts) between the two end points cannot send the client's certificate because it would never have access to the client's private key. Your options are to either
a) not handle SSL/TLS at the proxy
b) request the client cert at the proxy and find some other information to send to the server
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects