Forum Discussion
Do I Need The Client Private Key to Setup a Two-Way SSL Handshake?
I am trying to configure a two-way SSL authentication but am getting errors stating handshake failure. I need to know if, in the client SSL profile used, whether I need to import the client private(or public) key into the BIG-IP since it will have to present the key for authentication when request is made.
I am using the "require" option so the connection would fail unless the authentication succeeds.
Thanks for your assistance.
1 Reply
- Stanislas_Piro2
Cumulonimbus
In client ssl profile, you must set:
- Private / public key for resource provided by the F5 (like any client SSL profile)
- public key bundle of all trusted CA for client authentication
No need to include client private key... if you set this, it is not private anymore ;-)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com