Bug ID 482304: Prohibit configuring certificate/key on serverssl when SSL forward proxy is enabled

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
11.4.1, 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3, 12.1.0 HF1, 12.1.0 HF2, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:
12.0.0

Opened: Oct 02, 2014

Severity: 3-Major

Related Article: K32239061

Symptoms

SSL Forward Proxy does not support server side client authentication. When SSL Forward Proxy is enabled, a Server SSL profile configured with client SSL certificates does not send CertificateVerify. The result is SSL connection can not be established.

Impact

SSL connection cannot be established.

Conditions

A certificate and key on server ssl profile is configured, and forward proxy is enabled.

Workaround

This issue has no workaround at this time.

Fix Information

SSL Forward Proxy does not support server-side client authentication. The fix is to prohibit configuring key/certificate fields in server SSL profile when forward proxy is enabled.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips