Forum Discussion
Client use certificate to autenticate to Server
Hello,
Thanks for this but I don't now how I must configure Client SSL profile. Which certificat I must Use.
Thanks,
Janez
- Nov 26, 2019
You can use whatever Client SSL profile you want, because when using Proxy SSL, this certificate is ignored:
- BIG-IP copies same Server SSL/Back-end Server certificate to Certificate message sent to Client on client-side
- BIG-IP completely ignores certificate you configured on Client SSL. It always uses the same server-side certificate.
You should import the servers certificate and key:
BIG-IP has an extra configuration requirement for Proxy SSL configuration (according to K13385) that you should add the same certificate/key present on the back-end server to Certificate/Key fields on Server SSL proxy of BIG-IP. This way BIG-IP can decrypt both client and server sides of connection.
- BIG-IP copies same Server SSL/Back-end Server certificate to Certificate message sent to Client on client-side
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com