Forum Discussion
HTTP profile & SSL profiles not playing nice.
Does the server require client certificate authentication?
When you set a client/server SSL profile to Proxy, the TLS handshake is negotiated directly between client and the pool member, so that certificate-based mutual authentication works.
This situation can be quite difficult to resolve - you can set up certificate authentication on the Client-ssl profile, and require the client to present a certificate. You can also supply a client authentication certificate to the server-SSL profile, and present the server with a certificate for authentication.
But you cannot easily pass the specific client authentication certificate from the client to the server. This is a problem where the specific client authentication certificate has a role to play on the server. In some cases, you can configure delegated authentication on the server, and pass the client auth certificate in an HTTP Header, or similar, but it very much depends on the role the certificate plays and how the server is set up.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com