Forum Discussion
SSL Intercept SHA1 Certificate
- Jul 26, 2018
I opened a support ticket with F5 and the F5 engineer who answered the ticket made the following recommendation:
"configure a trusted certificate authority bundle in the server ssl profile. The default bundle contains many well-known public CA certs for server-side processing."
After I did this, the problem was solved.
Thanks.
Greetings,
We usually wait to publish bug details until there's a fix or workaround. Quite a few people are running into this, so it seems best to publish the bug details early. You may be able to request an engineering hotfix for this as well if you open a case with support:
K11425420: SSL Forward Proxy or F5 Herculon SSL Orchestrator may sign SSL certificates using SHA1 algorithm
https://support.f5.com/csp/article/K11425420
Hope this is helpful!
Kevin
Hi Stanislas,
That's frustrating. You'll have to open a support case to troubleshoot this. The feature has quite a few components, so it's difficult for me to say what's happening.
I did a customer case query and don't see any cases after 13.0.0, which is odd (if this is still happening).
Sorry I couldn't offer more help!
Kevin
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com