Forum Discussion
gkundu
Nimbostratus
Jul 27, 2018SSL Encryption with Default server ssl profile
How does SSL encryption happens with default server ssl profile?
Why does the certificate needs to be the same on LTM and pool members? Can the certificate on client-ssl profile and pool members have...
How does SSL encryption happens with default server ssl profile?
This is a really big question, can you perhaps offer a bit more focused question?
Why does the certificate needs to be the same on LTM and pool members?
The certificate configured on an SSL enabled (e.g. has a clientssl profile) does not need to match the certificate configured on the pool members. It's common to have a commercially signed certificate on the VIP and self-signed certificates on pool members.
Can the certificate on client-ssl profile and pool members have the same hostname but different intermediate and root certificate?
I can't see any reason why not. The serverssl profile, which controls negotiation of SSL between the BIG-IP and pool members doesn't need a validated certificate on the pool member, it just needs any certificate in order to be able to negotiate a connection.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects