Forum Discussion
APM SSL_VPN Certificate Check Failing
Some of our Corporate laptops have multiple local machine Certificates from the same CA installed on them. We are using these certificate to verify that it is a Corporate device when attempting to establish a VPN tunnel in via APM.
We are getting the error message "X509_verify_cert failed: error : 10 at depth 0, error message:certificate has expired" because the APM is finding the expired cert and not the new one on the laptop. Is there anyway to tell the APM to keep checking the LoaclMachine store location for the second Certificate? We are trying to find a work around until our Support team can remove the expired Certs from all the laptops.
2 Replies
- Seth_Cooper
Employee
Unfortunately there isn't much you can do from the APM side other than try to narrow it down to only find the valid search by looking for the issuer (which I assume will match both). APM will find the first certificate that matches the criteria in the VPE Action options and then test that certificate. If the expired certificate is found first then the process will error as that certificate is expired.
Would the certificates possibly be issued by a different CA? If so then you can limit the scope of the search.
If not it appears you need to advise your users to delete the expired certificate if they have issues.
Seth
- theXfactor82_91
Nimbostratus
Unfortunately they are issued by the same CA.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com