Forum Discussion
Forward Proxy and Client Authentication Certificates
ProxySSL would only work for inbound (reverse proxy) traffic, by virtue of the requirement to possess the server's private key.
But to answer your question, it depends on what you mean.
If you're talking about simple explicit forward proxy, where the client's TLS connection is performed between the client and real server, within the TCP tunnel created by the proxy after the CONNECT request, then yes that should work. Transparent forward proxy would also work.
If, however, you're talking about transparent or explicit SSL Forward Proxy, wherein the F5 decrypts and re-encrypts the SSL between the client and server, then vehemently no. The only way to perform mutual PKI (client certificate) authentication is to completely bypass SSL processing at the proxy for this traffic.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com