Forum Discussion
Does it require to install root Cert in F5 for server SSL?
Hi,
I am trying to configure server ssl. the pool member are listening on port 443 and i need to create SSL certficate. The vip url is myvip.mycompany.com and i have generated client SSL and install it in F5 for offloading. Now i need to create server SSL but what certificate i need for that? How F5 will encrypt?
-Jinshu
1 Reply
- nathe
Cirrocumulus
Jinshu,
Not 100% certain of the question. But if you want to re-encrypt the data from the bigip to the backend pool member then the default serverssl profile will work. It will use the certificate/key on the pool member to encrypt the traffic. This default profile doesn't care about the name of the cert as it doesn't do that type of checking (check the server authentication section of the profile and you'll see "Server Certificate" is set to ignore. If you want to check the certificate supplied by the web server you can do by specifying the above setting is require and then referencing the "Trusted Cerificate Authorities" section.
Is that what you mean?
N
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com