Forum Discussion
Arun_Bhardwaj_1
Cirrus
Feb 05, 2015can we open login f5 through http and block https? so will not get SSL error.
can we open login f5 through http and block https? so will not get SSL error.
We are having link load balancer. And during security audit in our company we are shown SSL vulnerablity on public I...
Eklas1974_20500
Nimbostratus
Aug 25, 2015Hello,
I am getting (SSL Certificate - Signature Verification Failed Vulnerability) only for the cert in which there are multiple subjects (Subject Alternative Name) ...this specific cert is used to multiple stage envs ( it's like a bundle)...
any idea if there is anything special I need to do for this cert to pass the scan?
- StephanMantheyAug 25, 2015
Nacreous
Hi, you are using a SAN certificate as device certificate? It should not be a problem. Make sure the name used as CN is contained in the list of alternative names as well. In case it contains IP addresses the labels in the alternative names should be IP instead of DNS. For a device certificate it is very important to have both the purpose flags to act as server cert and as client cert. Does the GTM trust the signing CA? Is the certificate imported to device certs, trusted certs and to GTM server trusted certs? On weekend I can upload a script covering creation of a cert containing alternative names, being valid for 10 years, based on 2.048 bit key and copies it to all required locations. Thanks, Stephan
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects