Forum Discussion
Michael_A__Fied
Nimbostratus
Aug 02, 2010Using the Server SSL Profile with an intermediary CA
I have a distinct feeling that I am overlooking something straightforward and simple.
We are attempting to secure our back-end web traffic, and have set up the following:
- ClientSSL profile "ServiceName" issued by RootCA
- ServerSSL profile "TrustRootCA" is "defaults from serverssl", and the CA certificate "ca file rootca.crt"
- Virtual Server has profile "ServiceName" and "TrustRootCA" attached to it.
This is pretty striaghtforward, and typically works when the TargetNode (apache) has a certificate issued from RootCA as well.
Where it seems to break is when the TargetNode has an Apache ssl profile issued by IntermediaryCA
- IntermediaryCA has been issued a CA cert from RootCA
- TargetNode has cert from IntermediaryCA
Attempting to connect to the Virtual Server provides the following:
This is driving me up the wall.
- hoolio
Cirrostratus
Hi Michael, - Haarith_Devaraj
Nimbostratus
Not sure if this is the answer you are looking for. To insert the intermediate CA, you can go to the profiles, ssl, choose the client | server certificate and choose advanced.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects