Forum Discussion
Client Certificate is not passing through back end hosts
So just to clarify, your fastL4 isn't doing any SSL, so you're just passing SSL directly between the client and backend server, and of course client cert auth should work. Are you load balancing between multiple backend servers, and if so how are you maintaining persistence?
You simply CANNOT pass the client's certificate to the backend server if you terminate the SSL at the proxy, for the reasons I described before. ProxySSL can work in this regard, but you must force the client and backend server to only negotiate with non-PFS RSA, which is becoming harder to do as user-agents are starting to completely deprioritize (and ultimately remove) non-PFS ciphers.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
