Forum Discussion
CVE 2020-5902 Point Release with VS Client Authentication
Just upgraded LTMs from version 12.1.3.0.0.378 to 12.1.5.2 Build 0.0.10 Point Release 2.
Have VSs that request Client Authentication, and an iRule that loops through the client certs, and scrutinizes the certificates.
The Point Release delivers the client certificates in a different format than version 12.1.3.0.0. This caused the iRule to reject the certificates.
So if you have a VS that request and examines client certificates, and are going to install a version that fixes CVE 2020-5902, please be aware that you may have to edit you iRule to look for a slightly different format.
- jaikumar_f5
Noctilucent
Yes I've encountered this too. I had to change the Irule in my case.
- OTS02
Cirrus
Thank you jaikumar_f5 for article K14204621.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com