Forum Discussion
SSL Handshake failed - client certificate authentication and also without certificate
Hello,
Proxy SSL is problem because customer use ECDHE or any ciphers with Perfect Forward Secrecy.
Here is client profile:
ltm profile client-ssl /Common/client-SSL {
app-service none
ca-file /Common/Cert.crt
cert /Common/Cert.crt
cert-key-chain {
Cert_chain {
cert /Common/Cert.crt
chain /Common/Cert_CA.crt
key /Cert-Key.key
}
}
chain /Common/Common/Cert_CA.crt
cipher-group none
ciphers DEFAULT
defaults-from /Common/clientssl
inherit-certkeychain false
key /Common/Cert-Key.key
passphrase none
peer-cert-mode request
ssl-c3d enabled
}
And Server profile:
ltm profile server-ssl /Common/Server-SSL {
app-service none
c3d-ca-cert /Common/Cert.crt
c3d-ca-key /Common/Cert-Key.key
cert /Common/Cert.crt
defaults-from /Common/serverssl
key /Common/Cert-Key.key
ssl-c3d enabled
Thanks and regards,
Janez
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com