f5-appsvcs-extension icon indicating copy to clipboard operation
f5-appsvcs-extension copied to clipboard

Add Support for serverssl-use-sni Option in Virtual Server Configuration

Open ppieprzycki opened this issue 1 year ago • 9 comments

Is your feature request related to a problem? Please describe.

I would like to request support for the serverssl-use-sni enabled option within the Service_HTTPS configuration. This feature is usefull for handling scenarios where backend servers utilize Server Name Indication (SNI) with multiple certificates.

Describe the solution you'd like

I would like to see the equivalent functionality of the following command in the configuration: tmsh modify ltm virtual <virtual_server> serverssl-use-sni enabled

Additional context

For further details, please refer to the following Knowledge Base article: https://my.f5.com/manage/s/article/K13452

ppieprzycki avatar May 26 '24 16:05 ppieprzycki

@ppieprzycki FYI I have opened a support case and received an existing ID 1579129 [RFE] Add support for 'serverssl-use-sni' option in TLS_Client

amolari avatar May 29 '24 08:05 amolari

@ppieprzycki please refer to https://github.com/F5Networks/f5-appsvcs-extension/issues/274

We added a default value to under the SSL profile to select with is default. Use the serverssl-use-sni' option when having multiple. Pre AS3-44 the top profile would be default.

mdditt2000 avatar May 30 '24 20:05 mdditt2000

Closing this issue as resolved in AS3-44 as per above

mdditt2000 avatar May 30 '24 20:05 mdditt2000

@ppieprzycki please refer to #274

We added a default value to under the SSL profile to select with is default. Use the serverssl-use-sni' option when having multiple. Pre AS3-44 the top profile would be default.

#274 is for client-ssl profiles (TLS_Server) "inbound" SNI support. This issue is for the new-in-BIG-IP-v15 server-ssl (TLS_Client) "outbound" SNI support.

Totally different features.

wncocz avatar May 30 '24 21:05 wncocz

@ppieprzycki can we setup a quick call. I think i understand what you looking for but want to confirm. Please ping me [email protected] for 15 min zoom call. I want to add this in AS3-53 which begins early July!

mdditt2000 avatar Jun 13 '24 20:06 mdditt2000

AUTOTOOL-4415 has been created for intrernal tracking

sunitharonan avatar Jun 13 '24 20:06 sunitharonan

Is there any progress on this? This is the option that's being requested https://my.f5.com/manage/s/article/K39408450

t0m3kf avatar Feb 04 '25 17:02 t0m3kf

Seconding this request for the virtual server level serverssl-use-sni in https://my.f5.com/manage/s/article/K39408450

npmaslow avatar Feb 10 '25 20:02 npmaslow

AUTOTOOL-4415 has been created for internal tracking

sunitharonan avatar Apr 04 '25 18:04 sunitharonan

Any update on this??

Sakorah avatar Aug 05 '25 09:08 Sakorah

The issue is resolved in AS3 55 release. Available shortly

mdditt2000 avatar Oct 29 '25 14:10 mdditt2000