Forum Discussion
CraigMo
Nimbostratus
Dec 03, 2015rewriting client ssl server name
If a user enters, for example, is there a way to intercept or manipulate the ssl handshake such that the "" is changed to "https://abc.123.com"? Currently the valid cert on the F5 is for abc.123.co...
StephanManthey
Nacreous
Dec 03, 2015Hi,
TMOS supports both certificates withsubject alternative names (aka SAN certificates). So just request a new cert containing not only the common name in the subject but also the common name and additional names in the subject alternative names extension.
In addition the new TMOS version suport server name indication (aka SNI). Its an extension to TLS which is putting the expected CN into the clients SSL hello message.
This information will be used to pick the right client-ssl profile.
Just use multiple client-ssl profiles in context of your virtual server definition supporting the different hostnames you expect.
Thanks, StephanHelp guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects