Forum Discussion
Mark_22062
Nimbostratus
May 18, 2012CRLDP LDAP no Hostname
Our internal CA is AD based, with CDP configured with http URI and ldap URI. When trying to use CRLDP it errors out because the ldap URI entry in the certificate has no hostname (under Windows if there is no hostname it assumes AD).
Rather than rejigging the PKI infrastructure is there some way to intercept this with iRules and insert a hostname? OCSP is another possibility but would require deployment of some more servers.
4 Replies
- ccb
Employee
Hi Mark,
Did you manage to find a solution? - Mark_van_D
Cirrostratus
Hi Clinton,
Not as yet, once I find one I'll let you know. - KC_106957
Nimbostratus
Hi Mark,
I think you can add an extra ldap URI with hostname without rejigging your KPI infrastructure. ldap://hostname/...
My windows admin changed it for me, the only problem I have is that during the client SSL authentication phase the LTM/APM tell's me that the client certificate is self signed by my internal Root CA.
How did you overcome this in your setup?
Thanx,
Kees - Mark_van_D
Cirrostratus
Hi Kees,
I haven't made any progress on this.
Cheers
Mark
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects