Bluemix Secure Gateway - internal service using HTTPS, and TLS mutual auth outside? -
i'm comfortable basics of bluemix secure gateway, can't see way set must surely common scenario.
my requirements are:
- existing internal service provided on tls, , must remain so. doesn't check client certs, it's conventional https:// rest api.
- external end of secure gateway pipe must check client certificates, allow known clients connect.
the second point achieved choosing tls mutual auth option when setting destination in secure gateway ui. however, creates tls connection client app (actually browser @ point) internal end of secure gateway pipe. comes out end of pipe, towards internal service, plain http in clear. internal service rightly rejects this, it's expecting https.
i can make working connection configuring secure gateway no tls, , tls connection client browser way internal server, problem here bluemix pipe wide open on internet throw things @ internal server, , although know "trusted internal network" ought myth, fact thing never set internet-facing. want block except known client @ outer end of bluemix pipe.
i think need way internal end of pipe, running in docker image, start second tls session internal server. seems necessary feature, can't find reference in docs. or there other way i've missed?
since posting this, i've got in touch 1 of bluemix developers (i'm ibmer - option may not available :-) ). answer is not supported, real now.
i daresay there ways hook openssl s_client or similar stream, supported version close enough not worth complexity, me.
Comments
Post a Comment