Forum Discussion
Resign certificate for clients to server with SSL Offload?
SSL Forward Proxy is intended for outbound (forward proxy) connectivity, where you do not own the server and its certificates. In this case, SSL Forward Proxy forges (resigns) the remote server certificate to internal clients. So for example, an internal client surfing to https://www.google.com would get a Google certificate resigned by a local CA.
I believe what you're asking for is reverse proxy connectivity, where external clients are accessing internal web services. Minimally you need a client SSL profile (client-facing) that contains the certificate and associated private key that are exposed to the client making the HTTPS request. For the server side, F5 to web server, you usually don't need anything here except a generic serverssl profile. The server (web server in this case) possesses the certificate and private key, so the F5 would be the client in this case. You'd only need to insert a cert and key in the server SSL profile if the server required mutual (client certificate) authentication.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com