Forum Discussion
Silicon_84874
Nimbostratus
Jan 24, 2012SSL Authentication by server side
Hi All,
I'm looking to implement an SSL re-encryption but need to have the real server perform the SSL authentication checks. I know the F5 can perform this check via an iRule, but security policy mandates that no one should be able to query the real server directly. Can someone please point me in the right direction?
I'm currently on v10.x code. I've been told that v11 offers "proxy SSL"?
I'd appreciate any suggestions.
2 Replies
- hoolio
Cirrostratus
Hi Silicon,
In 11.0, we added support for Proxy SSL where you configure the server SSL cert(s)/key(s) in server ssl profile(s) and enable Proxy SSL on a client and the server SSL profiles. TMM then goes into a pass through mode for the SSL handshake so the server receives the actual client cert when it's requested. After the initial handshake, TMM is able to decrypt the bulk crypto and access the decrypted content for use with LTM, iRules, WAM, WOM, etc. Make sure to use the most current 11.x code and latest hotfix as there have been a couple of recent fixes with this feature.
Aaron - Silicon_84874
Nimbostratus
Thanks Aaron, I'll go down the most current v11 code +HF.
Regards,
Silicon
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects