Loading...
Loading...
In SSL reverse proxy, dynamic CRL checking for client certificate is not working when TLS 1.3 handshake is used. The SSL handshake successfully completed even though the client certificate is revoked.
The handshake should fail but complete successfully
-- Dynamic CRL checking enabled on a client-ssl profile -- The client-side SSL handshake uses TLS1.3.
None
The issue was due to Dynamic CRL revocation check has not been integrated to TLS 1.3. After the Dynamic CRL checking is integrated to TLS 1.3, the TLS handshake will work as expected.
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.