Forum Discussion

_Mo__2's avatar
_Mo__2
Icon for Nimbostratus rankNimbostratus
Sep 26, 2018

IMAP(s) with SSL Offloading with Client Certificate Authentication

Hi,

 

I would like to know if it is possible to put in place a VS on the port 993 + SSL Client Profile with Require enable to force the email client to provide a client certificate.

 

When the client will be authenticate by the F5, I will forward the IMAP Connection to the backend on the port 143.

 

Do you know if it's working like that ?

 

Thanks a lot. Morgan

 

1 Reply

  • Hi,

    As you know IMAP is an application layer Internet Protocol using the underlying transport layer protocols to establish host-to-host communication services for applications. This allows the use of a remote mail server. The well-known port address for IMAP is 143.

    So in fact IMAPS (IMAP over SSL) allows IMAP traffic travel over a secure socket to a secure port, typically TCP port 993.

    Internet IMAP port 993 SSL <> F5 Load balancer + Cert auth <> Exchange port 143

    But I think that the problem will come from App client (messaging app) that can't negociate auth using a cert.

    it's like the exchange client using OutlookAnywhere. cert auth was not possible in spite of the ssl / tls...

    the best way is to test but I do not believe in this type of deployment

    hope it's clear. regards,