Forum Discussion
Tim_Corbett_752
Nimbostratus
Sep 08, 2005HTTPS verification on the server side?
I just tried moving our first bigger site to our F5's today which includes a shopping basket that is secured through SSL (the whole site is not secured). I set up the certificates on the F5 and configured the SSL profile to do the decrypting before the request got to the server. However, I discovered that our deveopers were doing their own checking to make sure the basket URL's were secure, and if not were redirecting the browser back to https://
This created an endless loop since the F5 was doing the decryption and the server was always just seeing the plain text http request.
What I'm wondering is if any of you guys have seen this before, and if so how you solved it? Our developers are hesitant to remove the checks on their end, but we want to be able to reap the benefits of having our SSL certificates centralized, and at the same time don't want to necessarily have to make a ton of code changes.
Any thoughts / suggestions are welcome. Thanks!
- unRuleY_95363Historic F5 AccountMany implementations insert either the whole client certificate or some of the client certificate fields in a separate header so that the backend can track the client certificate.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects