Forum Discussion
Client authentication random failure - 11.6 HF4
Sorry, but I'm having a hard time following what you're saying. Certificate authentication can fail in a number of ways, so I'm trying to eliminate some of these through my line of questions.
For example, certificate authentication can fail if:
- The SSL handshake fails for any reason
- Validation and trust can't be confirmed
- There's a bad CRL
- You're requesting the client cert in the client SSL profile and in the APM On-Demand agent
- The On-Demand agent is failing
Since you have the APM On-Demand agent set to request, then verification and trust shouldn't be an issue. If you have no CRL applied, then revocation shouldn't be an issue. If some clients work on the broken platform, but not others, then it's probably not an SSL handshake issue. Again, it's important to focus on the BROKEN platform, not the loaner. And I'm not sure what certificate expiration has to do with this. If no clients work on the broken platform, then it could be something wrong with the access policy or even the SSL handshake. If the fallback branch message box shows the certificate subject, then you're probably looking at something wrong with the On-Demand agent.
Can you provide a screenshot of your visual policy?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
