Forum Discussion

Pamela_Pelletie's avatar
Pamela_Pelletie
Icon for Nimbostratus rankNimbostratus
Apr 19, 2006

SSL certificate

Hi, I have 2 SSL cetificates. Each of them have a different name but they are used for the same IP address. I've create a pool which include 2 nodes with 2 different IP addresses. For the virtual server, I need help : there's CNAMEs associated with the same IP address. I wanna be able to choose which certificate to load when one of the CNAME is choosen. Is it possible? An iRule?

2 Replies

  • Deb_Allen_18's avatar
    Deb_Allen_18
    Historic F5 Account
    I don't think that would be possible even with an iRule, since the Host: header is encrypted until after the handshake, and the hostname must be known to choose the proper certificate for the handshake.

     

     

    /deb
  • Look into TLS SNI

     

    Not all Web Browsers support TLS SNI. Enforcing TLS SNI today will cut off the automatic web-site trust for about 0.3% of end-users that have legacy Web Browsers. These clients will receive an untrusted site warning, and must confirm a security exception to proceed to visit the site.

     

    Do not blindly take this number as a fact, this is what I've personally observed in my customer environment. If you are in Health Care business where the majority of customers are elderly people with outdated Windows XP desktops, you may want to avoid implementing this technology :)