Forum Discussion
Secure www to Secure NON www
Hello all.. Here is my conundrum.. I need to be able to redirect a https://www.domain.com request to https://domain.com. I have an irule in place and it's working, however the enduser receives a cert warning when the redirect happens saying that the "www" is not valid because the cert is not for that domain name. Though the end user can continue on by accepting the warning message the customer does not want this to be prompted, don't really blame them. Anyway I thought my problem was the iRule and found out, in a different post, that the SSL handshake happens before the irule goes into effect so my irule redirect is correct. Originally we were using a wildcard SSL cert on this site's VIP "*.domain.com", however I've since gotten the actually domain.com cert, installed it in the LTM, setup the Client and Server SSL profiles and assigned those profiles to the VIP. But the end user receives the same message. The back end server is IIS, actually a SharePoint 2010 farm. I've also changed the binding in IIS to use the domain specific cert vs the wildcard, but when the redirect happens to the non WWW they get a cert warning saying it's requesting a non www on a www cert. Make sense? I'm at a loss at this point, any suggestion on what I might be missing here?
Thanks, Bob
6 Replies
- Kevin_Stewart
Employee
None of the server side SSL should handshake stuff will be visible to the client, unless the BIG-IP and server cannot successfully negotiate SSL. The error that the client is seeing is most likely because the subject of the certificate presented to the client during its handshake with the BIG-IP is not that same server name that the client asked for. There's very little you can do to mitigate this other than getting a server certificate that matches the name the client is using.
- Bob_10976
Nimbostratus
Thanks again Kevin..
Is moving back to the wildcard cert an option, maybe at least in the interim? Otherwise like Kevin said, you'll need to get a new cert with the correct subject..
- Bob_10976
Nimbostratus
They are currently using the wildcard.. I'm looking into a different cert with the correct subjects. Thanks
- JRahm
Admin
if you have both certificates *.domain.com and domain.com, you can use TLS-SNI to switch ssl profiles and this error will be invisible. This of course requires that all your clients honor tls-sni, which most do, though a notable exception is any IE version on XP.
- Bob_10976
Nimbostratus
Thanks Jason.. I actually got it resolved by adding the Subject Names to the *.domain.com cert. Though thanks for replying it's good to know in case we run into this again that might be an option.
Thanks, Bob
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com