Forum Discussion
Chip_Hudgins_64
Nimbostratus
Jun 17, 2005SSL client profile based on hostname
Is there anyway to select or change the SSL client profile based on hostname?
If is easy to find the hostname in an HTTP_REQUEST but then how could you set the SSL client profile? I am trying to have one VIP for multiple SSL sites each with different SSL certificates for each.
Thanks in advance.
21 Replies
- Gauthier_Delac1
Nimbostratus
Hi,
It's not easy because user agent header is sent after SSL handshake (even with SNI).
But in this iRule (http://devcentral.f5.com/Tutorials/TechTips/tabid/63/articleType/ArticleView/articleId/1086451/Multiple-Certs-One-VIP-TLS-Server-Name-Indication-via-iRules.aspx), you can use detect_handshake variable to know if SNI has been used.
Then depending on what you call "kick", you can use this variable in any other event to handle unsupported clients the way you want.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
