Forum Discussion

wesweber_98132's avatar
wesweber_98132
Icon for Nimbostratus rankNimbostratus
Mar 10, 2009

GTM-LTM Not Exchanging Cert

I'm trying to connect a LTM, running 9.3.1, to a GTM, running 9.4.3. The GTM has a self-generated cert and the LTM has privately generated cert.

 

I ran big3d_install and bigip_add on the GTM to update the big3d daemon on the LTM and get the LTM's cert. When I ran iqdump on the GTM to verify the exchange I get the error message: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed:s3_clnt.c:844

 

Running iqdump on the LTM show the GTM cert.

 

The F5 site kb has doc SOL6692 that seems to describe the problem but says the problem was fixed with ver 9.4.2.

 

 

Any ideas as to what may be happening here?

3 Replies

  • Deb_Allen_18's avatar
    Deb_Allen_18
    Historic F5 Account
    Reading CR67836, it looks like the fix mentioned simply added the Certificate Depth setting, but the default is still 0. Apparently it needs to be set to a value between 1 and 9. A value of 2 was suggested as a possibly saner default, so I'd start with 2.

     

     

    I just updated the solution, should be re-published including that detail shortly.

     

     

    /deb

     

     

  • I'm searching for CR67836 on the F5 KB and the doc itself isn't coming up. Also, is the depth setting made at the CLI or the Config gui.
  • It is set in the GUI under System->General Properties->General->Certificate Depth