Forum Discussion
Dazzla_20011
Mar 25, 2011Nimbostratus
Server-side SSL
Hi,
Currently we only do client-side SSL on the F5. I've been asked if we can encrypt the traffic from the F5 to web servers. I know the F5 can do server side ssl so just wonderered if someone could confirm the follwing steps are correct to do this?
Install a certificate on the web servers, a self signed certificate should be OK.
Create a server side SSL profile on the LTM.
Apply the SSL profile to the Virtual Server
It seems very simple, am I correct?
Also could this have any impact on the ASM as we are just starting to set this up?
Thanks
Darren
- fLyf5_21542NimbostratusIn continuation to above discussion; I have received server certificate generated( based on server csr) by CA and need to configure server SSL profile in LTM.
- nitassEmployeeShould it require Importing server key; or is it ok to upload only the certificate. to do ssl offloading, we need both certificate and private key.
- fLyf5_21542NimbostratusHi nitass
- nitassEmployeesorry to confuse you. i might misunderstand you a bit.
- We use SSL offloading, and we have the cert and private key on most of our profiles, but we noticed when we generated one from an internally signed CA, we didn't get the private key, but we were still able to do the full SSL offloading that we would with any of our other sites that have both the cert and key.
- fLyf5_21542NimbostratusI was checking serverssl profile configuration & have not seen option to send f5 certificate ( client certificate) to server.
- nitassEmployeeI was checking serverssl profile configuration & have not seen option to send f5 certificate ( client certificate) to server.it is certificate and key setting.
- fLyf5_21542NimbostratusBig Big thanks to you nitass, I am clear with the ssl process now :)
- nitassEmployeeIs it a good idea to import server certificate to my LB, though I am not going to map it with any of the profile.if i were you, i wouldn't import it (since you know it is not used).
- fLyf5_21542Nimbostratushe he , thanks man.
Recent Discussions
Related Content
Â
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects