Forum Discussion
SSL certificate
- Deb_Allen_18Historic F5 AccountI don't think that would be possible even with an iRule, since the Host: header is encrypted until after the handshake, and the hostname must be known to choose the proper certificate for the handshake.
- Hannes_Rapp
Nimbostratus
Look into TLS SNI
- Background: https://devcentral.f5.com/articles/ssl-profiles-part-7-server-name-indication
- Configuration: https://support.f5.com/kb/en-us/solutions/public/13000/400/sol13452.html
Not all Web Browsers support TLS SNI. Enforcing TLS SNI today will cut off the automatic web-site trust for about 0.3% of end-users that have legacy Web Browsers. These clients will receive an untrusted site warning, and must confirm a security exception to proceed to visit the site.
Do not blindly take this number as a fact, this is what I've personally observed in my customer environment. If you are in Health Care business where the majority of customers are elderly people with outdated Windows XP desktops, you may want to avoid implementing this technology :)
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com