Forum Discussion
Will_Adams_1995
Nimbostratus
Oct 18, 2015Client authentication random failure - 11.6 HF4
We have a pair of BIG IP 6900 appliances that work as an active/passive HA pair. Recently we have upgraded the appliances to 11.6 HF4 (we were on 11.3 HF10) and have been having issues with our clie...
Kevin_Stewart
Employee
Oct 18, 2015So it appears that the On-Demand Cert Auth agent is failing. Let's try a few things:
-
After the successful and fallback branches of the On-Demand Cert Auth agent, add some message boxes. After successful:
"Success: %{session.ssl.cert.subject}"After Fallback:
"Fallback: %{session.ssl.cert.subject}"If you see the certificate subject in the fallback branch message, then you know the client sent a cert, and that the SSL handshake succeeded.
-
You have "Request" set in the access policy On-Demand Cert Auth agent and the in the client SSL profile? If so, don't do that. The client SSL profile should be set to Ignore.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects