Aug 09, 2023

Bug ID 878641: "TLS1.3 certificate request message does not contain CAs" not fixed?

BigIP Version:

Hello community,

when trying to configure Client-Certificate-Authentication in a clientssl-profile with "Advertised Certificate Authorities" we found that with TLS1.3 the list is empty:

openssl s_client
=> No client certificate CA names sent
when using TLS1.2 it works:
=> Acceptable client certificate CA names
<list of CAs>

This looks exactly like which lists just 15.x as affected and as fixed. Our box uses
Could someone explain what that means? Versions 16.x are not known to be affected or "should" be fixed in 16.x as well? The KB lists all versions as affected, however.

Can someone confirm the bug in versions 16.x?


  • Rooti The easiest way to see if a bug exists for your device and the configuration it is running is to create a QKVIEW and upload it to iHealth. This could be a similar bug but slightly different so it has a different bug ID but this would absolutely show up in iHealth when you upload the QKVIEW.

      PauliusThanks for the good advice. iHealth lists no Bugs regarding TLS1.3.

