Quantcast
Viewing all articles
Browse latest Browse all 42

Express Service Gateway - SSL Security without Client Cert.

 

We have setup an invocation agent to call a third party web service which runs on https.

[Internet] >> Input Server >> Invocation Agent>>ssl>> [ThirdParty Host]

Once handshake is done, the external server sends the server certificate to ESG.

This is followed by ESG sending the client certificate (Asymetric keys, configured under Security Configuration) to the remote server.

The external server is not configured to receive client certificate (mutual auth) and so it responds with [FIN, ACK] packet (which means close connection) and ESG closed the connection..

Is there any way on ESG to configure the Security such that it doesn't sends client certificate. 

Note - on Http Agent configuration, 'Our End Key Pair' is Mandatory, if we use SSL Security Policy.

Appreciate any help. Thanks !


Viewing all articles
Browse latest Browse all 42

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>