Layer7 API Management

  • 1.  Use the Policy Manager GUI via Apache Proxy

    Posted Nov 14, 2018 02:25 PM

    Trying to connect to the gateway from the Policy Manager GUI via Apache Proxy over SSL on Linux

     

    Getting:

     

    "The SSL/TLS handshake with the Gateway has failed"



  • 2.  Re: Use the Policy Manager GUI via Apache Proxy
    Best Answer

    Broadcom Employee
    Posted Nov 14, 2018 04:55 PM

    Please start by reviewing this document Start the Policy Manager - CA API Gateway - 9.1 - CA Technologies Documentation as it outlines how to use a proxy for the Policy Manager. You will need to change the http to https in the name i.e. https.proxyHost

     

    Sincerely,

     

    Stephen Hughes

    Broadcom Support



  • 3.  Re: Use the Policy Manager GUI via Apache Proxy

    Posted Nov 14, 2018 05:39 PM

    How do I get the gateway to authenticate using the user cert instead of the proxy cert?



  • 4.  Re: Use the Policy Manager GUI via Apache Proxy

    Broadcom Employee
    Posted Nov 14, 2018 05:52 PM

    As the Apache Proxy would terminate the SSL there is no a way to do client mutual authentication from the Policy Manager client and the API Gateway. 

     

    Sincerely,

     

    Stephen Hughes

    Broadcom Support



  • 5.  Re: Use the Policy Manager GUI via Apache Proxy

    Posted Nov 14, 2018 07:05 PM

    Stephen,

     

    Any other recommendations how to connect policy manager to the api gateway via a proxy?

     

    Thanks.



  • 6.  Re: Use the Policy Manager GUI via Apache Proxy

    Broadcom Employee
    Posted Nov 14, 2018 07:13 PM

    The information I provided is really the only settings that can be used but you would need to use username and password to log into the policy manager due to the inability for the policy manager to talk directly to the gateway.

     

    Sincerely,

     

    Stephen Hughes

    Broadcom Support



  • 7.  Re: Use the Policy Manager GUI via Apache Proxy

    Posted Nov 15, 2018 08:52 AM

    How would I access the gateway using username/password by going through the Apache proxy using SSL? What cert would the Policy Manager use? How would I configure Policy Manager to use the correct cert? We are trying to stay on port 443 to the Apache Proxy.

     

    Thanks



  • 8.  Re: Use the Policy Manager GUI via Apache Proxy

    Broadcom Employee
    Posted Nov 15, 2018 12:59 PM

    Good morning,

     

    I wanted to outline what has been spoken about so far. In the initial setting that I sent through around setting up Proxy for the Policy Manager involves a proxy that is in forward mode not reverse proxy. When the proxy is in reverse proxy mode it will terminate the traffic on one side of the proxy and reestablish on the other side. We have not tested with a reverse proxy for usage with the Policy Manager.  

     

    Sincerely,

     

    Stephen Hughes

    Broadcom Support