Forum Discussion
Jon_Wallwork_46
Nimbostratus
May 13, 2008Methods for selecting SSL Profile
Hi All
We have a customer who would like to do the following: I think its not possible but thought one of you guys will know more than me.
They have only one IP address and they would like to choose the SSL Certificate to use based upon which site is being requested.
I think that because the SSL Negotiation has to occur BEFORE the F5 can look at the HTTP host or URI there is no way of doing it.
Can anyone tell me i'm wrong and there a simple way of dealing with this?
Regards Jon
- The_Bhattman
Nimbostratus
You are absolutely correct. - Lightspeed_VT_5
Nimbostratus
This might be a dumb question, but why wouldn't something like this work?: - hoolio
Cirrostratus
You can't read the host in the HTTP headers until the SSL has been decrypted. You can't decrypt the SSL until you present a cert to the client and the SSL handshake is complete. In 9.x, you could select a client SSL profile but you need to know which one to present before you decrypt the SSL. In 4.x, there isn't anything that comes close to this.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects