Forum Discussion
Philip_Lee_6609
Nimbostratus
Sep 21, 2007SSL cilent certificate authentication
We have a web application (BigIP LTM -> iplanet web servers -> websphere application server).
The web application requires client certificate authentication and HTTPS.
We want to terminate the SSL in the BigIP and would like to do the client certificate authentication in the web server. Is this possible? So far, i can't get it to work.
The other option is to turn on client certificate authentication in the BigIP and pass the client certificate to the web server. Of course, the client certificate authentication is turned on in the web server.
I have tried to turn off client certificate authentication in the web server and turn on client certificate authentication in the bigip ltm and use irule to pass the client certificate in base64 format but that doesn't work..
any other options??
- Deb_Allen_18Historic F5 AccountThere are several examples in this forum of doing that using the session table to store client cert variables & re-inserting them as headers -- is that what you're having trouble with, or have you taken a different approach?
- Lars_Terje_Vaal
Nimbostratus
Hi. Í have the same problem - Do you need to pass /a/ client certificate to the back end server, or do you need to pass /the/ client certificate to the back end server to complete the handshake?
- Lars_Terje_Vaal
Nimbostratus
Hm. - Kirk_Bauer_1018
Nimbostratus
The BIG-IP can not possibly utilize the real client's certificate for the server-side connection because it does not have the key associated with that certificate as the client does not share that information. If you need the server to see the real client's certificate then you will not be able to terminate SSL on the BIG-IP. You can just pass it through untouched so the client and server can talk directly to each other.... the BIG-IP can still do load balancing, but no layer 7 functionality. - Lars_Terje_Vaal
Nimbostratus
Yea. Didn't think of the private key... :-) - Garrett_Skjelst
Nimbostratus
I'm interested in seeing the configuration that you're using to accomplish steps 1-5 if you are alright with making something like that available. - zafer
Nimbostratus
How can i do with SSL termination - zafer
Nimbostratus
How can i do with SSL termination - zafer
Nimbostratus
How can i do with SSL termination
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects