Forum Discussion
MW1
Cirrus
Jul 05, 2010...most likely a stupid Q by a stupid person
Sorry to be asking such a basic Q but wondering if anyone can shed some light/point me in the direction I need to look regarding setting client authentication using SSL certificates. We have internall...
hoolio
Cirrostratus
Jul 05, 2010There isn't really any additional debug you can enable. You can capture a tcpdump and decrypt it using ssldump to get more info on what's failing. Try searching the forums here and support.f5.com for ssldump for details on using the command.
I think you're correct that the the client cert request is probably still failing with the mode set to request.
You should add the CA (and intermediate cert) to a bundle and configure it as the advertised and trusted CA bundle on the client SSL profile. The advertised bundle tells the client what CA issuers will be accepted. The trusted CA bundle is what LTM will use to validate the cert.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects