Forum Discussion

Ajit's avatar
Ajit
Icon for Altostratus rankAltostratus
Feb 17, 2018

How serverssl works in serverssl profile F5 ltm

Hello F5 Experts,

 

In the case where both client and server ssl profiles are enabled & the F5's are in a sandwich design (i.e. One behind the other)

 

How does encryption/decryption happen in the following serverssl scenarios; where mutual auth is also enabled at both ends of the profiles.

 

1- There is no certificate in server ssl profile, there is certificate on the server.

 

2- There is certificate in server ssl profile, there is certificate on the server, both the certificates are same(Can they be same?)

 

3- There is certificate in server ssl profile, there is certificate on the server, both certificates are different(Do they need to be diff?).

 

Thanks,

 

Ajit

 

  • Answers to all three queries are Yes:

     

    1- There is no certificate in server ssl profile, there is certificate on the server.

     

    F5 is acting as a client (similar to browser)

     

    2- There is certificate in server ssl profile, there is certificate on the server, both the certificates are same(Can they be same?)

     

    ssl profile certs are used only when mutual authentication is configured. But it won't server any purpose.

     

    3- There is certificate in server ssl profile, there is certificate on the server, both certificates are different(Do they need to be diff?).

     

    they can be different cert for mutual auth.