Forum Discussion

Bhargav_9588's avatar
Bhargav_9588
Icon for Nimbostratus rankNimbostratus
May 09, 2007

CRL for SSL Client Profile

Hi,

 

 

I have configured SSL Client Profile (clientssl) with Certificate Revocation List (CRL) which has all the revoked certificate list. And assigned this profile to virtual server. When I access that virtual server using revoked ssl client certificate, F5 is accepting that certificate. Do I need to add any rule to check for SSLClientCertStatus header?

 

 

Please help me...

 

 

Thanks,

 

Bhargav
  • Colin_Walker_12's avatar
    Colin_Walker_12
    Historic F5 Account
    This sounds like something that would most likely be handled best by our Professional Services team. I don't believe there's any additional rule logic needed, but I'd create a case with them to diagnose the problem to ensure everything is configure properly Click here.

     

     

    Colin
  • It worked after adding [X509::verify_cert_error_string [SSL::verify_result]] in iRule.

     

     

    http://devcentral.f5.com/wiki/default.aspx/iRules/InsertCertInServerHeaders.html

     

     

    Thanks,

     

    Bhargav