Forum Discussion
Dazzla_20011
Mar 25, 2011Nimbostratus
Server-side SSL
Hi,
Currently we only do client-side SSL on the F5. I've been asked if we can encrypt the traffic from the F5 to web servers. I know the F5 can do server side ssl so just wonderered if someone could confirm the follwing steps are correct to do this?
Install a certificate on the web servers, a self signed certificate should be OK.
Create a server side SSL profile on the LTM.
Apply the SSL profile to the Virtual Server
It seems very simple, am I correct?
Also could this have any impact on the ASM as we are just starting to set this up?
Thanks
Darren
- nitassEmployeeI usually get certificate error whenever I access any page with self signed certificate, will f5 show similar behaviorif you mean serverssl, no if trusted certificate authorities is configured correctly. the default is none which means f5 will accept server (pool member)'s certificate signed by any ca.
- ArieAltostratus
Some suggestions:
- Depending on the security requirements, you may be able to save some cycles by using weaker encryption in the DMZ.
- Use the longest expiration the security requirements allow. In my experience many organizations purchase certs with a one-year expiration because of financial/budget consideration and/or uncertainty regarding the life span of the web site. Setting the self-signed cert to expire later saves some administrative overhead.
- Use the same self-signed cert in the DMZ for all VIPs if the security requirements allow it.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects