How Proxy SSL works on BIG-IP
1. Lab Scenario Lab test results: Client completes 3-way handshake with BIG-IP and BIG-IP immediately opens and completes 3-way handshake with back-end server Upon receiving Client Hell...
Published Sep 04, 2019
Version 1.0Rodrigo_Albuque
Cirrocumulus
Joined May 16, 2019
Rodrigo_Albuque
Cirrocumulus
Joined May 16, 2019
Eric_Chen
Employee
Sep 05, 2019Typically I see Proxy SSL for cases where the BIG-IP needs to proxy a client certificate authentication (mutual TLS). You mention the requirement for RSA key exchanges; that is not ideal to not be using ECC ciphers. Hopefully we'll see a follow-up article talking about C3D and the virtues of being able to re-generate a new client certificate that is trusted by the backend server as an alternate method to achieve the same end goal. Nice article!
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)