Forum Discussion

Chris_DiPietro_'s avatar
Chris_DiPietro_
Icon for Nimbostratus rankNimbostratus
Oct 03, 2014

2-way SSL from client to F5, will this work?

I want to use a self signed cert for 2 way SSL Virtual Server has a verified Cert for a real domain, this works fine in 1 way SSL

 

I installed a Self Signed Client Certificate I set Client Certificate to require

 

It does not appear to work, I either get a timeout or a generic SSL error

 

I have tried all the selections for Advertised Certificate Authorities non, ca-bundle, default, the SSL cert I am expecting the client to have and no luck.

 

any help?

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    Chris. Off the top of my head you need to configure Trusted Certificate Authorities. In here you need to specify the CA that the bigip trusts and can verify against when the client presents its certificate ie the CA that has signed the client cert.

     

    The Advertised option is when the bigip tells the client which CAs it will accept. This is optional.

     

    See if that helps.

     

    N