Forum Discussion
Switch off Trusted CA Check for Client Cert Authentication
We have BigIp breaking SSL and redirecting the requests to a backend server. We want to support client cert authentication, but the Trusted CA check should not be done on the BigIp but on the backend system. The certificate chain of the client certificate and the client certificate is sent as HTTP header to the backend server.
Is there a way to switch off this feature and just terminate the ssl and check whenever the ssl peer is in possesion of the private key and leave the certificate trust logic to the backend?
If I put none as trusted CA list then SSL handshake fails with ca not trusted alert.
Best Regards,
Aleksandar
3 Replies
- nitass
Employee
is proxy ssl feature applicable?
sol13385: Overview of Proxy SSL feature
http://support.f5.com/kb/en-us/solutions/public/13000/300/sol13385 - Sencko_83194
Nimbostratus
Unfortunately there is no SSL support on the backend :-( - hoolio
Cirrostratus
Can you change the cert mode to request on the client SSL profile?
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com