Forum Discussion
soymanue
Nimbostratus
Oct 23, 2012Edge Client Internal Certificate Authentication
Hello
Is it possible to make the BIG-IP work as an Internal CA to issue user certificates that we would use for user authentication with APM and Edge client?
12 Replies
- What_Lies_Bene1
Cirrostratus
You've got the OpenSSL suite at your disposal so I don't see why not. - soymanue
Nimbostratus
Fine, how would the certificate authentication work on APM with Internal CA? - What_Lies_Bene1
Cirrostratus
I'm afraid I'm not too familiar with APM. Regardless, in general, I assume it would work however it works with any CA. You just need to use OpenSSL to generate the appropriate certificates and then configure APM as you would for a public CA but use your internal one. Sorry if that's not too useful; hopefully someone else can respond in more detail. - Manuel,
But if you chose to have BIG-IP issue certs, then checking their validity in APM is easy, since you have the CA - although you will lack the ability to revoke certs - there are no CRLDP or OCSP responders on the BIG-IP.
- soymanue
Nimbostratus
We're talking about a couple of hundred certificates. Now we are using an external CA (Windows 2003). The problem is that APM does not support Machine Certificates. Issuing user certificates with Microsoft CA is quite complicated. The own user must connect to the website, fill the form, and connect later to download the certificate. Then, he must send the certificate to his own email accout in order to install it on his iPhone/iPad. It the user is the company's CEO, it doesn't look the best way to do it. - Mike_61719
Cirrus
Posted By Manuel on 10/24/2012 10:12 AM - soymanue
Nimbostratus
Ok - liangwei_118810
Nimbostratus
how to download?
- soymanue
Nimbostratus
Hi
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects