Great day F5 Friends,
Currently, we use a wildcard certificate on all of our web servers which requires us to replace it when the certificate is expired. The Big-IP isn’t configured to “only” trust this certificate on these servers which is less secure.
Where I would like assistance in is how to configure my Big-IP’s to trust only our internal CA for those pools. *NOTE: I will configure GPO to auto-enroll the web servers for SSL certs and bind to IIS.
Is it as simple as uploading the Chain cert to the Big-IP and then create a server ssl profile pointing to that Chain cert and adding the profile to the VS?
Thanks for your time and energy in this.
Sincerely,
Paul Courtois
Hello,
Indeed it’s as simple as creating a new server SSL profile and assign it to VS.
You will need to set server certificate to require under server authentication and select the appropriate trusted CA. You have to upload the CA chain beforehand.
Check this myF5
Good day my friend. Awesome! Thank you. I’ll try this in my dev environment and update asap. Much appreciated. 👊
I created a server ssl profile, set the server certificate to “require” and set the appropriate trusted CA in Server Authentication. (I also have the F5 default “serverssl” profile active on the Virtual Server server profiles). I then updated the bindings on the Web Servers and restarted the service. It broke connections and I see Big-IP LTM logs similar to “Peer cert verify error: self-signed certificate in certificate chain (depth 2; …”. Not sure what is going on here. Change has been reversed for more discovery/testing.
You mean you applied 2 server SSL profiles?
Can you use only the new one? If no you need to let VS know which one to use in each request.
I just did the same in my Lab and worked fine
Happy Friday. Thanks for the suggestion. I have to keep the default serverssl profile on the VS as we have multiple applications running on the same VS. The new serverssl profile I’ve created is specifically for our internal web server pools.
How do I tell the VS which profile to use, iRule or in the ssl profile?
Happy Friday to yoo too @pcourtois
irule is you friend in this case
check this myF5
when HTTP_REQUEST {
set hostname [getfield [HTTP::host] ":" 1]
}
when SERVER_CONNECTED {
switch -glob [string tolower $hostname] {
"sitea.com" {
SSL::profile serverssl-siteA
}
"siteb.com" {
SSL::profile serverssl-siteB
}
default {
#default serversssl profile to be selected if Host header value cannot be matched with predefined values
SSL::profile serverssl
}
}
}
Copy that. You ROCK! Thank you. I’ll give this a try and update.