Forum Discussion
ryanph_121149
Nimbostratus
12 years agoSSL Offloading -> Certificate Unknown
Hi,
We were able to implement SSL offloading but recently required even the next flow of traffic to be https. Here's the flow:
Client browse HTTPS: VIP(1st) --> SSL Offloading --> HTTP node...
Kevin_Stewart
Employee
12 years agoAre you requiring client certificate (mutual) authentication at either VIP? It may be a good time to start an SSLDUMP capture to see exactly where the SSL is breaking:
ssldump -k [path to private key] -i 0.0 -AdNn port 443 [and any additional filters]
If you are requiring client certificate, you'll also need to make sure that the certificate that the client is presenting is trusted by virtue of the explicitly-assigned certificate authorities bundle in the client SSL profile.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects