Forum Discussion
bylie
Nimbostratus
Aug 08, 2019F5 SSL VPN machine cert check rules
Hi,
We're migrating to a new MS PKI and were wondering how the F5 SSL VPN client handles multiple local machine certs. Is there any overview of what the rules are in this case when not using any of the issuer, serial number, ... filtering? For example:
- When 2 valid machine certs are available which one gets picked?
- When 2 machine certs are available but one is expired does the expired one get picked or will the client ignore it?
the second question was a bug, but is solved now:
https://support.f5.com/csp/article/K56006335
as for which one is picked if both are valid i can't find an answer on. i kinda assume the first the client picks, but on what ground ... ask f5 support is probably most sure way.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects