For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Muhammad_Irfan1's avatar
Apr 09, 2015

SSL certificate using F5 with MS Exchange

I want to buy an SSL certificate from Certificate Authority website. Traffic from client to F5 is https and from F5 to CAS server of MS Exchange is also HTTPS. Should i order a certificate with SAN portion. F5 VIP in Comman Name and CAS server URL in SAN. I am right?

 

Right now i have put exchange previous certificate which has CAS server URL in CN in my client profile. But VIP is different from CAS server URL. Could this be the reason i am unable to make it work through RPC (outlook) but OWA is working fine.

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    When you use the BIG-IP to do SSL bridging for any application i.e. terminate ssl and then re-encrypt, you only need a certificate to match the host name in the client ssl profile - as this does the termination. The certificate on the backend can be an internal PKI certificate if you choose.

     

    Hope this helps,

     

    N