Forum Discussion
LTM 11.3 with APM: smart card authentication not working
If you are not receiving a prompt for certificates then it might be a ca certificate issue on the BIG-IP. One of the questions in the iApp is "Which CA certificate bundle do you want to use for your trusted and advertised certificate authorities?". The certificate selected for this question needs to match the trusted CA that issued the certificates contained in your smartcard, only the client certificates issued by the selected CA will be prompted for a pin.
To verify, make sure BIG-IP apm logging is set to debug (note this is pretty verbose, so if you are in production use caution) and run tail -f /var/log/apm during a connection attempt. Look for "Session variable 'session.ssl.cert.exist' set to '1'" which will confirm a cert was never received (as you would suspect since a pin prompt to open smartcard was seen) and a look for a note similar to: Following rule 'fallback' from item 'Start' to item 'On-Demand Cert Auth'
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
