Forum Discussion
Sonny
Cirrus
May 12, 2010Ignore "Extended Key Usage" field in Cert
Looking for help with an iRule to ignore a field in the cert. In particular, I want the F5 to ignore the "Extended Key Usage" field of the cert. Background info: I have a connection in which the server authentication is working fine but the client authentication is falling down and we have tested various scenarios and have found that if we can have an iRule that ignores that field in the cert. then the client authentication would work, too. Any help would be greatly appreciated.
6 Replies
- hoolio
Cirrostratus
Hi Sonny, - Sonny
Cirrus
Yeah, the client is currently using this iRule to check the validity of the cert.:http://www.openssl.org/docs/apps/ve...IAGNOSTICS:
26 X509_V_ERR_INVALID_PURPOSE: unsupported certificate purpose the supplied certificate cannot be used for the specified purpose.
- Sonny
Cirrus
The "extend key usage" field on the cert. is missing the blip that say it's client auth. as well as server auth. - Sonny
Cirrus
The 26 code didn't paste well...http://www.openssl.org/docs/apps/ve...IAGNOSTICS - hoolio
Cirrostratus
Hi Sonny, - Sonny
Cirrus
Thanks for the replying Hoolio. I ended up getting a new cert. and it worked!
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects