Forum Discussion
Tony_Augustine_
Nimbostratus
Dec 15, 2008How to configure BIG-IP to accept client certs from multiple CAs to the same VS
I have a Client SSL Profile set up for terminating 2 Way SSL at BIG-IP. However it is currently set up to only accept client certificates issued by a particular CA. Can I and if so how to configure the SSL Profile to accept client certificates issued by more than one CA.
I think client "cert ca property" of an SSL Client Profile is used to set up this. However looks like I can specifiy only one CA cert in that.
Any help would be appreciated.
- strongarm_46960
Nimbostratus
impossible, since it would mean associating multiple profiles to a VIP. - hoolio
Cirrostratus
I think you can concatenate multiple CA certificates in a bundle and configure the client SSL profile to use the cert bundle as the trusted client CA's option. Here is a snippet from the 9.3 config guide: - strongarm_46960
Nimbostratus
As usual, Aaron is completely right, I have done this many times, you just have to copy the contents including the ===beginning=== and ===end== of each cert and past it into a single file then associate that within your profile (SSL Profile (Client)). - Tony_Augustine_
Nimbostratus
Aaron - hoolio
Cirrostratus
Are you having problems with Windows line terminators being different from Linux? Windows using CR and LF while *nix uses LF. - strongarm_46960
Nimbostratus
... do - SteveMP
Nimbostratus
I know this is an old thread, but hoping maybe someone can chime in. I am attempting to get this working on Version 10.2.1. I was able to create the cert bundle and the key bundle, and a new profile using these bundles. I dont see any errors anywhere. But when I access the site from a browser, it seems that the browser only sees the first cert that I imported into the bundle. Is there anything else I need to do to get it show both? - Kevin_Stewart
Employee
You can't specify multiple server certificates this way. So just that we're clear, this thread is about accepting client certificates from multiple CAs. That's accomplished by adding all of the CA public certificates to a text file and applying that to the Trusted Certificate Authorities drop down of the client SSL profile. You can optionally use this "bundle" in the Advertised Certificate Authorities drop down, or tailor it so that only specific certificate choices are shown in the client browser.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects