Hardware SSL (BIG-IP) / IIS Detection

From: gf (noreply_at_comcast.net)
Date: 08/05/04

  • Next message: RG: "Win2k IIS5 FTP Server Error"
    Date: Thu, 5 Aug 2004 13:29:57 -0600
    
    

    We run BIG-IP from F5 Networks for traffic management and install our SSL
    certs on this device. When the page is decrypted
    on the BIG-IP and forwarded on to IIS in clear text, there is no way to
    programatically detect whether the page requested was
    secure or unsecure (looking at HTTP info). This is often useful to switch
    between HTTP and HTTPS (in the same domain) instead of hardcoding the
    protocol in website links.

    So my question is:
    1) Is there a way to setup this environment so that IIS knows that the
    incoming request was actually decrypted by the BIP-IP? Even though it was
    requested over port 80.
    2) If SSL traffic is routed from the BIP-IP to port 443 on IIS, is there a
    way to install a certificate on IIS that doesn't tax the CPU like it would
    normally when a cert is installed on IIS?

    In #2, we can route all the requests to port 443 on the IIS server, but in
    order for IIS to serve a request on this port, IIS has to have a cert
    installed.

    Hope my question make sense.

    Thanks.


  • Next message: RG: "Win2k IIS5 FTP Server Error"

    Relevant Pages

    • Re: Backup "pending request"?
      ... > and assign in IIS MMC. ... > a) remove all cert in your cert store ... the request and response from the CA only contain the public key, ...
      (microsoft.public.inetserver.iis.security)
    • Re: Backup "pending request"?
      ... > and assign in IIS MMC. ... > a) remove all cert in your cert store ... the request and response from the CA only contain the public key, ...
      (microsoft.public.inetserver.iis.security)
    • IIS does not listen on ssl port
      ... I have purchased a certificate for verisign and installed on IIS 5. ... I have reviewed the steps on how to install the cert and then set the ... website to require SSL but i do not want to do that until i know i ...
      (microsoft.public.inetserver.iis.security)
    • Re: x.509 cert for TLS testing
      ... Then copy the cert request file in the form on ... retrieve the certificate from the web page and install it on the ... I have a CA on my test domain which I created an SSL cert for my OWA. ...
      (microsoft.public.exchange.admin)
    • Re: Vodafone ConnectMe software conflict with IIS 5.1
      ... request it again it comes up with a 400 bad request error. ... Now going into the event log I get the message to do with IIS ... searching is normally a response for a dodgey metabase [for whatever ... every time I install ConnectMe IIS dies - regular as ...
      (microsoft.public.inetserver.iis)