Forum Discussion
jforaker
Mar 10, 2014Nimbostratus
Client SSL profiles using SNI not able to use the subject alternative name
We have a clientssl profile using a *.domain.com wildcard SSL certificate. This profile is set as the default for SNI. We also have specific clientssl profiles using the application specific SSL cer...
crraymond_14666
Apr 24, 2015Nimbostratus
It doesn't seem to accept commas in 11.5.2
- Michael_Voight_Aug 20, 2018Historic F5 Account
The 11.6.1 release notes also indicate the default for the server name field is now the SAN. Formerly it was the common name.
- Kevin_StewartAug 20, 2018Employee
But again, what really matters here is what's in the Server Name field of the client SSL profile. This is what the F5 matches the Client Hello SNI against. It's true that browsers are starting to require a SAN value in server certificates (ex. Chrome 58), but that's irrespective of the SNI-profile match.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects