Forum Discussion
Verify Client Certificates
Hi.
I have a system that need Client Certificates, the SSL profile is requesting one and a Irules to check is one supplies and is the correct bits, verifyed..... , the client Certificates are loaded and defines in the CA "requires" and advertised" bundles. Access is working correct as required.
But the client something generates the certificates incorrectly or not using the CA as defined in the bundles. The F5 dose generate logs "Crypto codec error: sw_crypto-1 Failed to verify PSS padding." and other crypted logs but it needs to Tech to find the log and still it is not clear what wrong. Anyone has a way - Irules/app/CLI to verifying client certificates and it fields that the client can call via a Web site? They don't want to supply us the keys so testing is very limited. A perfect solution would be a https site to check correct CA signing, "key usage" definitions, .... I think the "PSS" issues is a bad client key.
thanks
1 Reply
you can do tcpdump.
ssl setup details will be shown in the dump file.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com