For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Matt_Frost_1560's avatar
Matt_Frost_1560
Icon for Nimbostratus rankNimbostratus
Mar 17, 2015

Mac will not pass Issuer Cert to F5 APM On-Demand Cert Auth

We are wanting to enable cert auth on top of AD auth in our Access Policy. Here's what the Policy looks like:

 

Logon --> AD Auth --> Route Domain --> On-Demand Cert Auth --> Client OS --> Health Check --> Allow

 

We create a unique user cert from our Internal CA for each of our VPN users. The cert also includes the Issuer Cert.

 

Window computers have no problem logging in and supplying both the main user cert AND Issuer cert.

 

Macs only send the user cert. F5 only checks to see if the Issuer Cert is valid within the user cert. Since the Macs don't send the Issuer, they fail the On-Demand Cert Auth Item and are denied.

 

How do we get our Macs to send the Issuer cert that's associated with the user cert?

 

.

 

.

 

We are using a wildcard cert for our VPN site if that makes a difference.

 

On-Demand Cert Auth: "expr { [mcget {session.ssl.cert.valid}] == "0" }"

 

Client Certificate: "request" Frequency: "always"

 

Issuer Cert is installed on F5 so it is trusted and working with Windows PCs.

 

1 Reply

  • Have you tried to change the "certificate chain traversal" setting in the client ssl profile

     

    -- gianrico