Forum Discussion

soymanue's avatar
soymanue
Icon for Nimbostratus rankNimbostratus
Sep 25, 2012

IOS Edge Client Machine Certificate

According to Edge Client for iOS documentation, only Client Certificate Authentication is allowed.

 

We asked our F5 contacts if Machine Certificate Authentication (which is supported by Cisco Anyconnect) will be supported in the future.

 

They answered that this functionality will be included in the future. They added this:

 

"You can install a “device certificate” in key chain and have Edge Client present it as part of the authentication process in lieu of a user client cert. You can’t use both at the same time. Alternatively, you can embed the UDID or MAC address into the user’s certificate and compare it when the edge client authenticates…"

 

Unfortunatelly the didn't tell us know how to make Edge Client present that device certificate.

 

Can anybody help us?

 

Thanks

 

 

 

3 Replies

  • Manuel, Likely you already have your answer. The current iOS client will handle this for you in the settings of the VPN connection.

     

  • I'm bumping this thread since the initial post is very close to my question. I'm migrating my company iPad remote access from Cisco AnyConnect to F5 Edge Client (v2.0.4) for iOS. My 2FA solution requires the Edge Client to be in Web Logon mode. The iPad gets x.509 certificates (issued by the company CA) successfully from my MDM solution. I have enabled the "Use Certificate" option and selected my certificate in the Edge Client configuration. What I'm struggling with is how to configure the VPE to validate the certificate.

     

    When I add the On-Demand Cert Auth action to the VPE I get "The server address provided is not valid."

     

    Machine Cert Auth checks just fail. Those seem to be configured to access Windows machine cert stores anyway.

     

    The goal is to confirm that an iPad has a certificate issued from my company CA a validate the cert with with a CA Root Chain cert.

     

    Has anyone achieved this scenario?

     

  • I haven't been able to do it. I gave up. And although they told me that the functionality would be included in the future, I hope I'm wrong but I'm afraid it isn't available yet.