Loading...
Loading...
If the server certificate status is revoked, SSL forward proxy configured with a new server SSL profile might drop the connection.
BIG-IP client connections are reset.
-- New SSL forward proxy server SSL profile is attached to the virtual server. -- Revoked-cert-status-response-control is set to the default value (drop). -- Certificate status service (e.g., CRL/OCSP) is configured on the server SSL profile.
Change revoked-cert-status-response-control to ignore on the server SSL profile.
If ssl-forward-proxy is enabled for new server SSL profiles, and revoked-cert-status-response-control is not specified, it will automatically be set to ignore. Client connection go through and the client will see a forged revoked certificate status.
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.