Forum Discussion
Using LTM to hide an untrusted certificate
I'm new to F5/LTM, and I'm curious if this is possible.
There's an appliance owned by a external vendor that uses a self-signed certificate. The appliance serves up an HTTPS web page on TCP port 443.
The appliance also has a WebSocket (over TLS) connection on a different port.
I have network access to the appliance, but I'm not allowed to make any changes to its configuration.
Is there a way to have the client computer connect to the F5 with a trusted certificate, then have the F5 direct the request to the appliance without getting a cert error on the client?
The goal is to hide the untrusted certificate from the client. I only want the client to see the trusted certificate that's on the F5.
I want to do this for a secure HTTP connection and a WebSocket connection over TLS.
Hello,
Yes its totally feasible.
You will have to create 2 Virtual server.
1 for https and 1 for websocket port.
Both will present your valid certificate and reencrypt the traffic before sending it to the appliance.
You will also need to apply a websocket profile.
2 Replies
- Injeyan_Kostas
Nacreous
Hello,
Yes its totally feasible.
You will have to create 2 Virtual server.
1 for https and 1 for websocket port.
Both will present your valid certificate and reencrypt the traffic before sending it to the appliance.
You will also need to apply a websocket profile.
- Melissa_C
Moderator
Hello wavesmasher​,
Thank you for posting to our community. I do see it this post has been up for some time with no response or update. If the response from Injeyan_Kostas has answered your question, or you have found the answer you were looking for we would greatly appreciate if you would update your post to reflect that. This can help you and other members who may have the same questions down the road.
Thank you for being a part of DevCentral!
- Melissa
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com