Forum Discussion

andy220_332493's avatar
andy220_332493
Icon for Nimbostratus rankNimbostratus
Apr 27, 2019

SSL orchestrator

Dear F5 Whilst SSL orchestrator as man in middle box exposing own certificate against client web broswer there is always warning on broswer that is not possible verify certificate against Certification authority which is obvious if certificate is faked by SSL orchestrator. Other words if SSL orchestrator works in conjunction with some Data Loss Prevention system such certificate error unveils for some bad insider guy in company that SSL is manipulated and decrypted by some middle box on way. So just simple question is there some smart solution on SSL orchestrator side which can overcome such its drawback and ensures that SSL orchestrator will remain hidden in a customer network?

 

2 Replies

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    To workaround browser warnings the clients will need to trust the CA certificate creating the MITM certificate on behalf of the destination. That's what I thought anyway. Or are you talking about non-Corporate/domain devices who won't trust this certificate?