Forum Discussion
Steve_Brown_882
Mar 31, 2008Historic F5 Account
SSL Client Certificate question?
I have searched ask f5 and here to find out if it ispossible to forward a client certificate to the backnd while still terminating SSL at the LTM box. Basicaly we have a soap application that is authenticating soap traffic on the backend via client certificates. We need to ecrypt and decrypt on the ltm to direct traffic to the appropriate backend, but we need to then pass the client certificate to the backend. I could not find anything in the clientssl or serverssl settings that specified this or anything in the documentation.
1 Reply
- Deb_Allen_18Historic F5 Account
There is no mechanism by which to directly forward the client's certificate via the standard authentication process, since using the client's cert to establish the session would require the LTM to use the client's private key as well. (A man-in-the-middle attack, basically)
You can instead use the session table to store the certificate & send it to the server via headers, assuming your app can pick it up from there. Here's an example from the iRules codeshare:
http://devcentral.f5.com/wiki/default.aspx/iRules/InsertCertInServerHeaders.html
Click here
HTH
/deb
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
