Forum Discussion
Chip_Hudgins_64
Nimbostratus
Jun 17, 2005SSL client profile based on hostname
Is there anyway to select or change the SSL client profile based on hostname?
If is easy to find the hostname in an HTTP_REQUEST but then how could you set the SSL client profile? I am trying to have one VIP for multiple SSL sites each with different SSL certificates for each.
Thanks in advance.
- unRuleY_95363Historic F5 AccountWell, you have a bit of a "Which came first, the chicken or the egg?" problem here.
- rapmaster_c_127Historic F5 AccountThere actually is a way though, but it involves thinking a little unconventionally.
- Chip_Hudgins_64
Nimbostratus
thanks for the help. I figured as much. - Daniel_20901
Nimbostratus
Has anyone tackled this and made it work? If anyone has a sample configuration that would be great. - Colin_Walker_12Historic F5 AccountThis really isn't an issue with iRules or the BIG-IP. This is a protocol issue. There really is no "good" way to make this work, as you have to decrypt the traffic to have the HTTP data available, and by that time you can't choose which SSL profile to use, unless you re-encrypt.
- hoolio
Cirrostratus
- spark_86682Historic F5 AccountThe RFE CR to support the "server_name" extension from RFC3546 and RFC4366 is 94903. I would echo your request to have customers contact support in this matter.
- steve_88008
Nimbostratus
- hoolio
Cirrostratus
If you can get a single cert which is valid for all hostnames that resolve to the VIP address, then yes, you can decrypt all requests. This could be a wildcard cert or a cert which uses Subject Alternate Names (SANs). - steve_88008
Nimbostratus
any perference from an LTM standpoint?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects