Forum Discussion
SSL Client certificaet forward with BigIp
As Youssef states, ProxySSL can only be used if you can force the client and server to use a non-perfect forward secret (RSA) TLS handshake key exchange. This becomes harder to do as modern browsers remove RSA as an option, or when TLSv1.3 removes it completely.
The better option would be Client Certificate Constrained Delegation (C3D). This is a feature added in 13.1 that allows you to "forge" a client certificate to a local server. Using a local certificate authority certificate and private key that the server trusts, C3D consumes the client certificate, validates and checks revocation (OCSP, CRL), and then creates a new locally-issued client cert on the fly with all of the attributes of the original client cert, and presents that to the server. In this way you can continue to perform mutual auth on the server, and still explicitly decrypt and re-encrypt on the F5.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com