Forum Discussion

Mayank_Shukla's avatar
Mayank_Shukla
Icon for Altostratus rankAltostratus
Apr 19, 2016

When it is mandatory to use end to end SSL

When it is mandatory to use end to end SSL i.e. installing cert on both LB and real servers ? What are the restrictions in this setup ?

 

1 Reply

  • If you don't need to manipulate or inspect the data you can simply configure SSL on the back end server and allow it to remain encrypted as it passes the BigIP. If you need to look at the data or change it then you will need to have your cert installed in both places. As far as restrictions, you need to ensure that the ciphers you need are supported on both the serverside and clientside SSL profiles, and you should know that using client certs in that situation is painful at best (at worst it won't work). Other than that there aren't a lot of restrictions.