Forum Discussion

Ram_Khakurel_75's avatar
Ram_Khakurel_75
Icon for Nimbostratus rankNimbostratus
Nov 28, 2012

iOS edge client certificate auth

Guys

 

i have got iPad f5 edge client VPN in to apm using user and password login.

 

How cani have client certificate in iPad as part of auth for extra security?

 

What change do I make to the apm vpe.

 

I have Verisign ssl cert in apm portal already.

 

how can I have certificate in iPad so that only corporate device with certificate and user in a ad group can VPN in?

 

I need the certificate part to complete this.

 

2 Replies

  • First, you need to get the client cert to your device. Typically, this is done via MDM solution, but you can also just email yourself a cert in pfx format and install it on the device from email, or VPN in and obtain one via browser from your certificate enrollment service.

     

     

    Then, you would go to the profile definition on your EDGE client, flip Use Certificates switch to On, and select a certificate you want to use.

     

     

    Then, you can go to the VPE on the APM and add On-Demand Cert Auth action before your login page.

     

     

    And don't forget to add your Clieny cert's Trusted CA under client cert settings of then clientsideSSL profile that is applied to your virtual server. Should be all set.
  • Hi Michael,

     

    how do I get the client certficate for the IOS device?

     

    Do i generate from Big-ip?

     

    We have verisign ssl client certificate in the apm portal .in the client ssl profile attached to the vip ,got valid certicate and key and intermediate chain.

     

    For the client authenication whats the certificate we use.does this mean each user will have a separate certificate for their ios device for edge client?Its confuses me.

     

    cheers

     

    Ram