Forum Discussion

gorge_300427's avatar
gorge_300427
Icon for Nimbostratus rankNimbostratus
May 20, 2017

SSL certificate

Hi , May I please know that if you install a certificate on the F5 ltm on the client side , does it mean that you dont need any certificates on the server side at all , if you wish to send the traffic unencrypted on the server side. So are we actually saving on the certificate cost now , since the F5 needs only one cert vs like 3 certs if there were 3 servers

 

Thanks

 

2 Replies

  • Hi,

     

    If your are doing SSL Offload (BIG-IP is decrypting traffic from clients and send unencrypted to backend servers) then yes, only certificate you need is one for clientside SSL profile - could be one originally used by your backend server if CN or SAN fields are matching FQDN configured for your Virtual Server IP on BIG-IP.

     

    Piotr

     

  • Exactly. In fact, if you're talking about web servers, and server-side traffic is unencrypted - that is, plain HTTP - there is simply no technology for server to present a certificate, since TLS level is absent.