Forum Discussion
Virtual server with server side profile : Do I need a cert on the backend servers?
If your backend server running SSL you may need to add server ssl profile to Virtual Server. It also meaning you need certificate installed in your backend servers
- Ashish_M_Gupta_Aug 20, 2018
Nimbostratus
Thank you. So, it means even if I keep the default profile ‘serverssl’ with the default setting for the virtual server , I HAVE TO have the private cert on the backend server(e.g. IIS) and maintain them?
- Kevin_StewartAug 20, 2018
Employee
As Quantiti stated, this depends on whether or not you re-encrypt to the backend server. If you don't, then no serverssl profile is required. If you do, then the backend server must possess a server certificate and private key. Normally you'd can't enable an Apache or IIS server for encryption without specifying these.
But it's also important to understand that the cert and key on the backend server doesn't have to be a public, purchased set. You can very easily use a generic internally-crafted cert and key. The default serverssl profile is defined to ignore certificate trust errors.
- Kevin_StewartAug 21, 2018
Employee
SSL/TLS encryption relies on certificates and private keys. Any server that wants to do TLS MUST possess a certificate and associated private key. However, BIG-IP doesn't care what cert and key you use on the internal application server, as it will ignore any untrusted cert warnings. You can literally attach an internally-created self-signed cert and key to the web server that doesn't expire for 42 years.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
