Forum Discussion
Core_Matrix_174
Nimbostratus
Oct 22, 2012iRule to Decide which VS to use.
The point of this is that we have multiple domains and therefore need multiple SSL Client side profiles, as you can only have 1 SSL profile per VS we would need multiple VSs. This would mean having t...
hoolio
Cirrostratus
Oct 22, 20121. Websense probably has a root cert/key that the browser trusts and can therefore generate a server cert/key dynamically for the requested hostname. Without TLS SNI, the requested hostname could be determined by Websense making a request (with TLS SNI if the client used it) or the IP address and checking the subject(s) in the server cert.
2. The client is using TLS SNI to tell the server in the unencrypted portion of the client hello which hostname it is requesting. If all of your clients support TLS SNI you could use this feature on LTM to support multiple server certs on the same virtual server.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects