Forum Discussion
SM_80821
Nimbostratus
Jun 25, 2010F5 end to end ssl with Win2k8R2 doesnt work
Hi
I have following topolgy where end to end ssl does not work with F5 proxy.
client (winxp or any)--[ssl]---F5--[ssl]--Server (windows2008R2)
-Just ssl termination on F5 and clear text on backend works
-End to end ssl with any other server like 2k3 or linux works
-With any cipher on w2k8R2 (RC4-MD5,AES128-SHA[default]) doesnt work. Handshake fails (actually TCP RST from F5 server side) after server sends CCS/Finished.
Has any one faced similar issues before? Any ideas, how to fix this?
Thanks
SM
- George_Watkins_Historic F5 AccountHi SM,
- SM_80821
Nimbostratus
Yes. I have the virtual with both client-ssl and server-ssl attached. - hoolio
Cirrostratus
If you do an ssldump looking for the serverside connection, what do you see in the handshake attempt? - SM_80821
Nimbostratus
Thanks for the reply. - hoolio
Cirrostratus
Can you post an anonymized copy of the ssldump output? If you connect directly with a browser to the server via HTTPS does it work? - Michael_A__Fied
Nimbostratus
Hey gang, I had a similar issue recently, and it turned out that the server-side certificate was too big, according to SOL11743 Good luck! - hoolio
Cirrostratus
I think the 2048 bit cert/key limit is only for certs and keys that you import into LTM (and only for versions lower than 10.2.0). So server side SSL shouldn't be affected by the server using a 4096 bit cert/key. It would break if you were usng a client cert/key in the server SSL profile that was over 2048 bits.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects