Forum Discussion

chin_15339's avatar
chin_15339
Icon for Nimbostratus rankNimbostratus
Apr 07, 2017

2 way ssl help

2 way ssl help , can someone share the steps on how to configure 2 way ssl the backend server is apache. when I authenticate directly to the server the two way ssl handshake works perfectly fine but then when I select the option require under the client profile of f5 it does not work

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    Chin, have you seen this askf5 solution Troubleshooting client certificate authentication, does this help?

    Bear in mind that if your backend server is still expecting SSL traffic and client authentication then you will need to modify your server SSL profile too with a certificate. See Overview of the Server SSL profile.

    The Certificate setting is optional. The default value for this setting is None. When you apply a Server SSL profile to a virtual server, the BIG-IP system acts as an SSL client. If you do not intend for the BIG-IP system to present its client certificate on behalf of clients traversing the virtual server, select None. If you expect the BIG-IP system to present a client certificate, import the certificate and matching key to the BIG-IP system, and then choose the appropriate certificate from the menu.

    Hope this helps,

    N