Forum Discussion
f5 APM edge client for IPHONE 8.1.3
Hi Folks:
Need some help with repect to the APM.
We are doing cert auth here is the APM policy
We are getting denies all the time I have uploaded the CA cert.
When we use the safari browser we get allow.
When we use the client we receive the following error:
Can I get some with the validation of my config and the expected behavior
Thanks,
Rahim
9 Replies
to recap, using iOS 8.1.3, when you use safari browser on the iPhone it works, but with the edge client on the same iPhone it doesn't?
why do you use the different cert inspection items? does it still work on safari when you change that to client cert inspection?
- Rahim_Damji_184
Nimbostratus
I made it a very simple APM policy
And changed the SSL CLIENT policy to request cert and through the browser I got the following successful message
When I test the exact same configuration with the edge client
I changed to ODCA browser looks good
with client same result
What troubles me is that the receive info on the edge client is WIN which makes scratch my head.
Thanks for response.
Rahim
- Seth_Cooper
Employee
Hi Rahim,
Please follow this guide for On-Demand cert auth for iOS.
You need to have the client ssl profile set to "ignore" and the on-demand cert auth set to "required".
Please try this and let us know if it fixes your issue.
Seth
- Gianrico
Employee
Have you selected "use certificate" and the certificate in edge client configuration on the iphone? Just to be sure all pieces are ok.
gianrico
- Rahim_Damji_184
Nimbostratus
Yes client cert has been checked off
Seth I will adjust the parameters accordingly and let you know
Rd
- Rahim_Damji_184
Nimbostratus
Adjusted accordingly same result turned on the debug does looks like the OCDA agent is working on the edge client as I do not see any cert authentication in the debug logs.
The browser is working fine.
- Gianrico_D_Ang1Historic F5 AccountEnable apm log level to "informational" and look at the session variables content in /var/log/apm
- Rahim_Damji_184
Nimbostratus
I upgraded to VE 11.5.2 and have had some better testing thanks for your help.
- Rahim_Damji_184
Nimbostratus
I upgraded to VE 11.5.2 and have had some better testing thanks for your help.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com