Forum Discussion
gkorah_32913
Nimbostratus
Oct 27, 2009SSL Cert Error with Mainframe
I have SSL offloaded from couple of my internal web servers to the F5-LTM. I was able to test it by connecting externally & opening a https to the virtual server & everything seems to work well.
One of my customers use a mainframe to post orders on the website (now offloaded to the LTM) & they seem to have a issue b'coz the error they see from the LTM is an unknown certificate. It seems to work fine with a web browser but not with their CICS server.
TCPDUMP shows the following error -
TLSv1 Record Layer: Alert (Level: Fatal, Description: Certificate Unknown)
Anyone having any idea on this would help a lot.
--
KC
- hoolio
Cirrostratus
Hi, - gkorah_32913
Nimbostratus
Thx for the post, Aaron. The only thing different is that I imported the original cert to the F5 from the backend IIS server. - hoolio
Cirrostratus
Hi George, - gkorah_32913
Nimbostratus
Aaron - That's correct. SSL terminations were on happening on the servers till I offloaded that to the LTM. - gkorah_32913
Nimbostratus
would SSLv2 have anything to do with the cert error ? I did a packet capture and I did see the client use SSLv2 as part of the initial SSL handshake. - hoolio
Cirrostratus
The main difference between any two SSL clients is which root certificates they have in their certificate stores. As I suggested above, if the mainframe client was working when going direct to the web servers, it's probably an issue with the intermediate SSL certificate(s) LTM is configured to send to the client in the client SSL profile. You should be able to export the SSL certificates in the chain from a working browser or the web server, convert them to PEM format and append them to the intermediate CA certificate bundle on LTM and then configure that intermediate CA bundle on the client SSL profile you're using on your VIP. If you need help doing this, you could open a case with F5 Support. - gkorah_32913
Nimbostratus
Hi Aaron - looks like the client did not download a cert from us, from what i gather after talking to the server folks who are supporting this environment here. - hoolio
Cirrostratus
You could create a test VIP (even on the same IP, but a different port) to test the SSL cert chaining. Did you import the intermediate certificate(s) as well and include them in the client SSL profile configuration? If you change the cert file contents, you need to click save to load the change into LTM's memory. - gkorah_32913
Nimbostratus
Not sure of the intermediate certificates, b'coz all I got from the server folks was a pfx file w/ the key. - gkorah_32913
Nimbostratus
I just confirmed w/ the client that they are using a JAVA script to nail the SSL connection to the LTM. Hope this helps.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects