Forum Discussion
Nuruddin_Ahmed_
Cirrostratus
May 14, 2016Proxy SSL Cipher Suite
Hi,
I've been trying to make proxy ssl work from many days after a long research. I want to know if proxy ssl requires specific ciphers to be used? I am using DEFAULT for both client and server ...
Yann_Desmarest_
Nacreous
May 14, 2016Hello
What is the error message ?
AFAIK, the proxy ssl feature support only RSA.
No support for DH, EDH and ECC
- Nuruddin_Ahmed_May 14, 2016
Cirrostratus
Hi, What would be the appropriate line which i can write instead of DEFAULT in cipher suite filed for RSA? The error message seen on the explorer window, i still have not run the packet capture. I would do further troubleshooting once the cipher suits are correct. I am newbie :( - Yann_Desmarest_May 14, 2016
Nacreous
Unfortunately, as there is no ssl bridging nor offloading configured on the bigip, ciphers are negociated between the browser and the backend server - Nuruddin_Ahmed_May 15, 2016
Cirrostratus
just wanted to know one thing. in the server ssl and client ssl profile, we would be providing on the Server certification. I have a single certificate for web server authentication as well as for client authentication. Do i need to get a certificate for server authentication only which would work? - Yann_Desmarest_May 15, 2016
Nacreous
On the clientssl profile, you should let everything default from the default clientssl profile except that Proxy SSL feature is checked - Yann_Desmarest_May 15, 2016
Nacreous
On the serverssl profile, you need to assign the same private key/certificate used by the backend server and have Proxy SSL checked. If there is client certificate authentication, the configuration should be done on the backend server. Nothing else needed on the bigip - Yann_Desmarest_May 15, 2016
Nacreous
In terms of Best Practices, you should have different certificates for ssl server authentication and client certificate authentication. X.509 purposes should not be the same. Also, pay attention that your certificates CA issuers are trusted on each peer. Some system/browser reject client cert auth if there is untrusted certificates - Nuruddin_Ahmed_May 15, 2016
Cirrostratus
Thanks Yann, i would try this solution today. - Nuruddin_Ahmed_May 15, 2016
Cirrostratus
I got this error - Configuration error: SSL Proxy state on clientssl profile(s) and/or serverssl profile(s) doesn't match on virtual server As per the document, i think, proxy ssl should be enabled on both. - Yann_Desmarest_May 15, 2016
Nacreous
Hi, Yes, of course proxy ssl should be activated on both
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects