Forum Discussion

Osama_Ibrahim_M's avatar
Osama_Ibrahim_M
Icon for Nimbostratus rankNimbostratus
May 03, 2016

Unaple to access the application

Dear Friends,

 

Recently I configured new application with SSL certificate, the certificate in .pem not crt, the system accept that and showing the expiry date. but I can't access through V.IP but through URL it can access.

 

Please can you advice.

 

Thanks,

 

4 Replies

  • Just a query, when you say through VIP its not working, i suppose your getting the Certificate page, (proceed to continue at your risk), if this is the case, do you have the VIP as the SAN name configured. This will not throw you the cert page.
  • BinaryCanary_19's avatar
    BinaryCanary_19
    Historic F5 Account

    URL means DNS name? if yes, then:

     

    This means that your backend server is only configured to accept the domain name as Host Header, and not IP address. You need to review your backend server configuration.

     

    -- URL means direct to application server? If yes then:

     

    this means that your virtual server configuration or Routing configuration in your network is not correct for your environment. Potentially, enabling Source Address Translation (Automap) could help. Otherwise, more details about the failure including error messages seen would be needed. If you're uncomfortable with posting that on a public forum, I suggest you open a support case with F5.

     

  • If I understand well, You`ve applied a certificate to a virtual server: -with FQDN it is OK, not giving a cert error -with IP address it is giving a cert error

     

    This is how it should be, the FQDN should match with the common name field in the certificate.

     

    Solution: Provide the FQDN in the common name field, plus provide the IP address as a Subject Alternate Name (SAN). The con of this solution if in the future You change the IP address for the virtual, the cert error will came back.