Forum Discussion
Need value for session.ssl.cert.valid
Kevin, just for my information, I have the same problem on another Virtual Server, so the idea was to do exactly the same, but there is an Application Security Policy on this VS.
When I change the setting (same change as for the other), I have this error:
Is this some kind of a bug ? I do not get what could be the problem with the security policy (it is only a SSL client profile change)
- Kevin_StewartNov 07, 2018Employee
Could simply be an mcpd validation error. What is the policy doing, and what happens if you try to remove the policy first, change the SSL profile, and then re-add the policy?
- LIH_admin_22571Nov 07, 2018Nimbostratus
I was about to do exactly that, but I do not really know what this policy is doing, and I am afraid that I will not be able to re-add the policy :)
May I check something particular in the policy ?
- Kevin_StewartNov 07, 2018Employee
Nothing looks out of the ordinary. So can you replicate this behavior on a "dummy" VIP so that you're not affecting production traffic?
- LIH_admin_22571Nov 07, 2018Nimbostratus
Not at the moment nope, I will sync/backup the config on the inactive node, do the modifications (disable security policy, modify ssl profile, enable security policy), and if there is a problem I will sync with the old configuration on the inactive node
- LIH_admin_22571Nov 07, 2018Nimbostratus
I disabled the security policy for the 4 virtual server we had:
But same behavior when I change the setting...
So I think this is not the problem, weird, any idea ?
- LIH_admin_22571Nov 07, 2018Nimbostratus
I have a clue, but I guess I cannot fix this specifically, needs the whole upgrade... :)
- Kevin_StewartNov 09, 2018Employee
Ahhhh, you're talking about multiple client SSL profiles on the VIP (with different properties). I thought you were talking about some issue with client SSL and an ASM policy.
In that case, what you're experiencing is expected. All of the client SSL profiles on a VIP (until BIG-IP 14.0) must have the same attributes.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com