Forum Discussion
Mike_Rausch_628
Nimbostratus
Mar 17, 2010SSL Certificates and PKI
Our application allows users to log in to the web server using PKI certificates and all SSL offloading is done on the server.
I was wondering if you could have a client connect to the BIGIP to a Client Side SSL profile, have the BIGIP decrypt, use IRULES for specific tasks, re-encrypt and send to server and still allow the users PKI cert to pass through to the web server?
I did read that you can insert client cert info into the HTTP headers but I do not know much about that.
I am new to the SSL Certs on the BIGIP so any help would be appreciated.
Thanks
Mike
- hoolio
Cirrostratus
Hi Mike, - Brian_Thompson
Nimbostratus
Isn't this different now that SSL Proxy is an option in the SSL profile with the newer code? - Kevin_Stewart
Employee
Exactly! Given a copy of the server's private key, ProxySSL becomes a party to the key negotiation between the client and server so that it has a copy of the derived session key used for encryption. So while the BIG-IP is technically decrypting and re-encrypting, the client and server are completely unaware.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects