Forum Discussion

Kerry's avatar
Kerry
Icon for Cirrus rankCirrus
Feb 12, 2026

Verify Client Certificates

Hi.

 

I have a system that need Client Certificates, the SSL profile is requesting one and a Irules to check is one supplies and is the correct bits, verifyed..... ,  the client Certificates are loaded and defines in the CA "requires" and advertised" bundles.  Access is working correct as required.

 

But the client something generates the certificates incorrectly or not using the CA as defined in the bundles.   The F5 dose generate logs "Crypto codec error: sw_crypto-1 Failed to verify PSS padding." and other crypted logs but it needs to Tech to find the log and still it is not clear what wrong.   Anyone has a way - Irules/app/CLI to verifying client certificates and it fields that the client can call via a Web site?   They don't want to supply us the keys so testing is very limited.  A perfect solution would be a https site to check correct CA signing, "key usage" definitions, ....  I think the "PSS" issues is a bad client key.

 

thanks

1 Reply