Forum Discussion
ask_me_anytime_
Nimbostratus
Apr 15, 2010ServerSSL - SERVERSSL_HANDSHAKE not triggered on certificate check failiure ??
Hello,
during serverSSL handshake, i'm trying to log messages when pool member server ssl certificate is invalid (expired certificate ) and BIGIP rejects it.
In the serverssl profile, i set...
hoolio
Cirrostratus
Apr 15, 2010Hi,
SERVERSSL_HANDSHAKE is triggered when an SSL handshake is completed. If the server SSL profile is set to require a cert but it's not validated, I don't think the event will be triggered as the handshake hasn't completed. If you change the server SSL profile to not require a cert, do you see the event triggered? If so, you could try validating the server cert in the iRule and reject the connection for invalid certs.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects