Forum Discussion
end to end ssl
For both x-forwarded-for and irules we have to gain access to the encrypted payload to read data and make changes. The only way to do that is to have the private key and ssl cert installed so we can encrypt and decrypt the data (acting as the server in this case). If you don't need to have the traffic encrypted between the BigIP and the pool member, you are done at this point. If you want that traffic encrypted to the back end, you will need to install the cert and key on the back end server also. After we are done manipulating the data, we will contact the back end server as a client, reencrypt the data as normal and send to the pool member.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com