Forum Discussion

Sodamax's avatar
Sodamax
Icon for Altostratus rankAltostratus
Apr 03, 2023

2 Way SSL not working as client certificate length is 0

I have already config about Client certificate is request, But not working. Can anyone please help me or guide me.

8 Replies

    • Sodamax's avatar
      Sodamax
      Icon for Altostratus rankAltostratus

      I try to test with physical ip(not f5) it work!!

      When i change physical ip to vip(f5) it not work.

  • when you say "vip(f5)" do you mean the DNS name of the VIP? Can you ping that name? Is it the same as your "physical IP"?

    • Sodamax's avatar
      Sodamax
      Icon for Altostratus rankAltostratus

      No not same.

      vip(f5) it mean ip load balancer

      physical ip it mean DNS name

      Thanks

  • You have to explain your setup, as it is not clear.

    If you test different things, you get different results.

    VIP usually is a virtual server with an IP address.  A DNS name usually points to this IP address.

     

     

  • So, if I interpreted this correctly.

    Your current scenario has a certain service that requires SSL client authentication and is working as intended.

    You need F5 to proxy this traffic. Will it still forward traffic to "original" destination, or will it be a new service with a different fqdn? Also, do you plan on using F5 to offload the SSL from your original service, or do you still need encrypted comunication between f5 <> real server? 

    In your tests via F5, are you testing traffic "directly" with F5 IP or have you configured a "hosts file"/dns entry to point to F5?

    This will help us understand better which profiles are required and what options you should enable 🙂 

    Regards

    CA