ServerSslProfileBinding
{
"server_auth_crl_ids": [
"string"
],
"server_auth": "string",
"certificate_chain_depth": 0,
"client_certificate_id": "string",
"server_auth_ca_ids": [
"string"
],
"ssl_profile_id": "string"
}
A Certificate Revocation List (CRL) can be specified in the server-side SSL profile binding to disallow compromised server certificates.
server authentication mode
authentication depth is used to set the verification depth in the server certificates chain.
To support client authentication (load balancer acting as a client authenticating to the backend server), client certificate can be specified in the server-side SSL profile binding
If server auth type is REQUIRED, server certificate must be signed by one of the trusted Certificate Authorities (CAs), also referred to as root CAs, whose self signed certificates are specified.
Server SSL profile defines reusable, application-independent server side SSL properties.