# iControl Java API Certificate Mismatch Suppression - Is it possible?

**URL:** <https://community.f5.com/t/icontrol-java-api-certificate-mismatch-suppression-is-it-possible/9870>\
**Category:** Technical Forums\
**Tags:** design, icontrol, security, cloud, devops, vmware\
**Created:** [November 5, 2013, 8:41pm UTC](https://community.f5.com/t/icontrol-java-api-certificate-mismatch-suppression-is-it-possible/9870 "2013-11-05T20:41:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Demetrios\_Kalle](https://avatars.discourse-cdn.com/v4/letter/d/e9c0ed/32.png) [@Demetrios\_Kalle](https://community.f5.com/u/Demetrios_Kalle)\
**Post date:** [November 5, 2013, 8:41pm UTC](https://community.f5.com/t/icontrol-java-api-certificate-mismatch-suppression-is-it-possible/9870/1 "2013-11-05T20:41:48Z")

</div>

Hi,

I’m working with the Java iControl.jar file in a project, and am working with a freshly installed instance of BIG-IP 11.5. It appears that the certificate from the server reports ‘localhost’ as the host name.

This appears to be causing an error when I attempt to invoke get\_system\_information().

Is there any way to temporarily configure the iControl API to accept a hostname mismatch while in development mode?

Thanks for any tips!

The error that I m getting is:

AxisFault faultCode: {[http://schemas.xmlsoap.org/soap/envelope/}Server.userException](http://schemas.xmlsoap.org/soap/envelope/%7DServer.userException) faultSubcode: faultString: javax.net.ssl.SSLException: hostname in certificate didn’t match: \<10.105.135.50\> != faultActor: faultNode: faultDetail: {[http://xml.apache.org/axis/}stackTrace:javax.net.ssl.SSLException](http://xml.apache.org/axis/%7DstackTrace:javax.net.ssl.SSLException): hostname in certificate didn’t match: \<10.105.135.50\> != at org.apache.axis.components.net.JSSESocketFactory.verifyHostName(JSSESocketFactory.java:351) at org.apache.axis.components.net.JSSESocketFactory.verifyHostName(JSSESocketFactory.java:287) at org.apache.axis.components.net.JSSESocketFactory.verifyHostName(JSSESocketFactory.java:270) at org.apache.axis.components.net.JSSESocketFactory.create(JSSESocketFactory.java:216) at org.apache.axis.transport.http.HTTPSender.getSocket(HTTPSender.java:191) at org.apache.axis.transport.http.HTTPSender.writeToSocket(HTTPSender.java:404) at org.apache.axis.transport.http.HTTPSender.invoke(HTTPSender.java:138) at org.apache.axis.strategies.InvocationStrategy.visit(InvocationStrategy.java:32) at org.apache.axis.SimpleChain.doVisiting(SimpleChain.java:118) at org.apache.axis.SimpleChain.invoke(SimpleChain.java:83) at org.apache.axis.client.AxisClient.invoke(AxisClient.java:165) at org.apache.axis.client.Call.invokeEngine(Call.java:2784) at org.apache.axis.client.Call.invoke(Call.java:2767) at org.apache.axis.client.Call.invoke(Call.java:2443) at org.apache.axis.client.Call.invoke(Call.java:2366) at org.apache.axis.client.Call.invoke(Call.java:1812) at iControl.SystemSystemInfoBindingStub.get\_system\_information(SystemSystemInfoBindingStub.java:1784) at com.f5.\_interface.soap.SOAPInterface.connect(SOAPInterface.java:112) at com.f5.\_interface.soap.SOAPInterface.CanConnectToBigIP(SOAPInterface.java:136) at com.f5.plugin.iControlLocalLB.connect(iControlLocalLB.java:192) at com.f5.plugin.iControlLocalLB.retrievePoolList(iControlLocalLB.java:286) at com.f5.plugin.iControlLocalLB.verifyCache(iControlLocalLB.java:275) at com.f5.plugin.iControlLocalLB.getVirtualServers(iControlLocalLB.java:744) at com.f5.plugin.TestHarness.TestLocalLB(TestHarness.java:461) at com.f5.plugin.TestHarness.main(TestHarness.java:599)

```tcl
{http://xml.apache.org/axis/}hostname:VIEW51-W7PFIN06

```

javax.net.ssl.SSLException: hostname in certificate didn’t match: \<10.105.135.50\> != at org.apache.axis.AxisFault.makeFault(AxisFault.java:101) at org.apache.axis.transport.http.HTTPSender.invoke(HTTPSender.java:154) at org.apache.axis.strategies.InvocationStrategy.visit(InvocationStrategy.java:32) at org.apache.axis.SimpleChain.doVisiting(SimpleChain.java:118)

---

<div class="post-metadata">

**Author:** ![Joe\_Pruitt](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/joe_pruitt/32/8438_2.png) [@Joe\_Pruitt](https://community.f5.com/u/Joe_Pruitt)\
**Post date:** [November 20, 2013, 10:54pm UTC](https://community.f5.com/t/icontrol-java-api-certificate-mismatch-suppression-is-it-possible/9870/2 "2013-11-20T22:54:33Z")

</div>

The code should be in there to do that already. There is an implementation of an XTrustProvider that injects itself in the ServicePointManager and allows that case. What version of the iControl library for Java are you using? I’ll test it out and see if I can recreate the issue.

---

<div class="post-metadata">

**Author:** ![Demetrios\_Kalle](https://avatars.discourse-cdn.com/v4/letter/d/e9c0ed/32.png) [@Demetrios\_Kalle](https://community.f5.com/u/Demetrios_Kalle)\
**Post date:** [November 21, 2013, 6:59pm UTC](https://community.f5.com/t/icontrol-java-api-certificate-mismatch-suppression-is-it-possible/9870/3 "2013-11-21T18:59:48Z")

</div>

Hi Joe,

I’m fairly certain that I’m using the iControl 11.3 jar file.

Since posting this the appropriate certificates have been added and everything is fine now.

Cheers,

Demetree

---

<div class="post-metadata">

**Author:** ![janarthanan](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@janarthanan](https://community.f5.com/u/janarthanan)\
**Post date:** [August 5, 2020, 7:12am UTC](https://community.f5.com/t/icontrol-java-api-certificate-mismatch-suppression-is-it-possible/9870/4 "2020-08-05T07:12:57Z")

</div>

Hi Demetrios,

I also getting similar issue . what would be solution for that ?

Thanks and Regards,

Jana
