Forum Discussion

Jibinpv's avatar
Jibinpv
Icon for Nimbostratus rankNimbostratus
Feb 20, 2017

Mutual Authentication Error

Hi All, I was been deploying mutual authentication for one of the client services and have that sent it up for them. However once the client tries to connect to it they have issues with the certificate.

 

The way I have set it up is as follows. We have a VIP to which respective client authentication profile is been attached.

 

In profile , Under the client authentication Client Certificate - require Frequency - Once Retain Certificate - Enabled. Trusted Certificate Authorities - Have applied and bundle Certs Advertised Certificate Authorities - Certificated Provided by client.

 

I have done a log capture while client initiates a connection and following was the log I can see from F5.

 

warning tmm1[19702]: 01260006:4: Peer cert verify error: unable to get local issuer certificate

 

Any advise on this will be of great help as this something very new Im being doing for Mutual Authentication.

 

3 Replies

  • Have applied and bundle Certs Advertised Certificate Authorities - Certificated Provided by client.

     

    what exactly does this mean?

     

    also are you sure the client is sending the certificate?

     

  • Hi Boney, Im sorry the sentence alignment got messed up.Its a two different part like below.

     

    Trusted Certificate Authorities - Have applied bundle Certs

     

    Advertised Certificate Authorities - Certificated Provided by client

     

    Thanks for your time to have a look into the query and respond.

     

    We have the issues got fixed. It was related to the Bundle certificate which we have applied was not authenticating providing the respective error.

     

    Got the cert bundle from the client and have that applied to trusted certificate authorities.Which fixed the issue of Mutual authentication issues

     

  • thank for posting back Jibinpv, it was what i was going to suggest. the advertised is optional i believe. it is the trusted CA that matters.