Forum Discussion

Vishal_Sinha's avatar
Vishal_Sinha
Icon for Nimbostratus rankNimbostratus
Aug 26, 2020

Does using default clientssl profile disable SSL offload for the VIP?

I have a VIP that is using client ssl profile with default (localhost) certificate. my pool members for this VIP have the Certificate for this URL.

I see the certificate when i access the VIP.

I believe that i should receive a certificate error if SSL offloading is enabled on F5 but i dont see the error.

Why is that?

  • Can you check which certificate are you getting on the browser? when accessing VIP?

    • Vishal_Sinha's avatar
      Vishal_Sinha
      Icon for Nimbostratus rankNimbostratus

      i see a certificate that is installed on the pool member server. its a certificate issued by our Internal CA, and the VIP URL is included as SAN in that certificate.

  • If you have configured client SSL profile on the VS then client should get certificate present in the client SSL profile attached to the VS not the certificate present on the pool member. Are you sure if request is hitting correct VS?

  • yes, VIP has a Client SSL profile and i have default localhost certificate called in it. I have verified that we are hitting the right VIP. i did the tcpdump and saw the hits.

    i am seeing this thing on many of my F5s that have default certificate called in the Client SSL Profile.