Last Modified: Oct 04, 2024
Affected Product(s):
BIG-IP LTM
Known Affected Versions:
15.1.2.1, 15.1.3, 15.1.3.1, 15.1.4, 15.1.4.1, 15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 16.1.3.1, 16.1.3.2, 16.1.3.3, 16.1.3.4, 16.1.3.5, 16.1.4, 16.1.4.1, 16.1.4.2, 16.1.4.3, 16.1.5, 16.1.5.1
Fixed In:
17.1.1, 15.1.10
Opened: Jul 29, 2021 Severity: 3-Major
In logs the result of Dynamic CRL validation using SSL::verify_result is appearing as 0, which is not correct.
Incorrect information that certification validation is successful for a revoked certificate is logged.
1. Use Dynamic CRL 2. Use a REVOKED certificate
Static CRL method of certificate validation can be used.
iRule was configured to get certificate validation result. But it was getting called before validation. So with fix iRule deferred till validation result is available.