Forum Discussion
Server and client certificate CN should match or not in client authentication
- Nov 29, 2014
F5 certificate CN and Client certificate CN should match?
no, cn should not be the same because they authenticate different things (one authenticates server but the other one authenticates client).
I uploaded CA bundle through GUI but that is not shown in /config/filestore/files_d/Common_d/certificate_d
i understand it is correct. trust_certificate_d is for device trust.
F5 certificate CN and Client certificate CN should match?
no, cn should not be the same because they authenticate different things (one authenticates server but the other one authenticates client).
I uploaded CA bundle through GUI but that is not shown in /config/filestore/files_d/Common_d/certificate_d
i understand it is correct. trust_certificate_d is for device trust.
- Muhammad_Irfan1Nov 29, 2014
Cirrus
Nitass please stay with me. I am unable to work It out. My server authentication portion is working fine and green lock is shown when client access VS. But when I set it to require the hand shake fails 1. I have a ca bundle of the issuer. 2 intermediate and 1 root certificate in trusted certificate authorities in client authentication profile. 2. One which base F5 will authenticate client certificate? Only on the trusted certificate authority? or by some field in the certificate as users can have other certificates from the same certificate authority. 3. Do clients have to generate their own certificates and how on windows machine? I want to use one certificate for all clients. - nitass_89166Nov 29, 2014
Noctilucent
>One which base F5 will authenticate client certificate? Only on the trusted certificate authority? yes >Do clients have to generate their own certificates and how on windows machine? I want to use one certificate for all clients. as long as client certificate is valid, it should be okay. - Muhammad_Irfan1Nov 29, 2014
Cirrus
Ok I have certificate which is issued by mobilink uploaded it personal certificate tab in pfx format. Issuer of that certificate is already in F5 trusted bundle. How can I verify that browser is presenting that certificate when requested? That certificate is in the personal tab but if I set it to manual select the certificate I don't have that certificate in the drop down when selecting manual selecting the certificate - Muhammad_Irfan1Dec 01, 2014
Cirrus
It worked yes. I was using server authentication for the client authentication. As I tried with client authentication certificate it worked. Thank you for all the help
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
