Forum Discussion
Mac will not pass Issuer Cert to F5 APM On-Demand Cert Auth
We are wanting to enable cert auth on top of AD auth in our Access Policy. Here's what the Policy looks like:
Logon --> AD Auth --> Route Domain --> On-Demand Cert Auth --> Client OS --> Health Check --> Allow
We create a unique user cert from our Internal CA for each of our VPN users. The cert also includes the Issuer Cert.
Window computers have no problem logging in and supplying both the main user cert AND Issuer cert.
Macs only send the user cert. F5 only checks to see if the Issuer Cert is valid within the user cert. Since the Macs don't send the Issuer, they fail the On-Demand Cert Auth Item and are denied.
How do we get our Macs to send the Issuer cert that's associated with the user cert?
.
.
We are using a wildcard cert for our VPN site if that makes a difference.
On-Demand Cert Auth: "expr { [mcget {session.ssl.cert.valid}] == "0" }"
Client Certificate: "request" Frequency: "always"
Issuer Cert is installed on F5 so it is trusted and working with Windows PCs.
1 Reply
- Gianrico
Employee
Have you tried to change the "certificate chain traversal" setting in the client ssl profile
-- gianrico
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
