Forum Discussion
Mike_Harpe_6170
Nimbostratus
Jan 31, 2012DoD CAC authentication using IIS through LTM
I am working with developers and SA people to get an app that uses IIS authentication with LTM.
Basic setup is a virtual server on 443 with a cert on the front end, two servers on the back e...
hoolio
Cirrostratus
Feb 01, 2012If you can't modify the web app to either disable the client cert requirement or parse the client cert from HTTP request headers, you could use try Proxy SSL. It's a feature added in 11.0 which allows the client and server to negotiate the SSL handshake directly. But once the handshake is complete, TMM can decrypt the SSL and inspect/modify/optimize the decrypted application traffic.
The upside is that you can handle mutual auth through LTM without modifying the client or app. The downside is that you're not offloading the SSL from the servers to LTM.
Implementing Proxy SSL on a Single BIG-IP System
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-implementations-11-1-0/15.html
Make sure to use 11.1 with the latest hotfix as there have been some recent fixes.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
