<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACE SSL offloading &amp; Client certificate authentication in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784088#M15147</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, extracting values from the cert and insert into the HTTP Header did not made it in ACE2.0.&lt;/P&gt;&lt;P&gt;Next big release 3.0 should have it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Mar 2008 16:30:43 GMT</pubDate>
    <dc:creator>Gilles Dufour</dc:creator>
    <dc:date>2008-03-18T16:30:43Z</dc:date>
    <item>
      <title>ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784080#M15139</link>
      <description>&lt;P&gt;We have several webserver clusters secured with SSL and we use client certificate authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on the certificate, users have different rights.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment we use microsoft NLB but we want to implement SSL offloading on the ACE. However, if we remove SSL from our webservers we can not use client certificate authentication anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What solutions are possible to keep client certificate authentication ?&lt;/P&gt;&lt;P&gt;Is it possible to implement authentication on the ACE and send some header, which would include a user id to the webservers, or something like that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2007 11:53:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784080#M15139</guid>
      <dc:creator>sebastianvandijk</dc:creator>
      <dc:date>2007-05-09T11:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784081#M15140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anybody ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2007 11:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784081#M15140</guid>
      <dc:creator>sebastianvandijk</dc:creator>
      <dc:date>2007-06-18T11:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784082#M15141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i just found out cisco currently isnt support client authentication in SSL.&lt;/P&gt;&lt;P&gt;too bad, any view on when this functionality will be available ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2007 09:41:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784082#M15141</guid>
      <dc:creator>sebastianvandijk</dc:creator>
      <dc:date>2007-06-21T09:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784083#M15142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this functionality will come with software version 2.0 which should come out in november.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2007 11:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784083#M15142</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-06-22T11:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784084#M15143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any update on when version 2 will be available ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2007 09:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784084#M15143</guid>
      <dc:creator>sebastianvandijk</dc:creator>
      <dc:date>2007-11-27T09:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784085#M15144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;actually my first message was incorrect.&lt;/P&gt;&lt;P&gt;The target is early 2008 for A2.0&lt;/P&gt;&lt;P&gt;Nov was for Ace appliance software on CCO. A1.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2007 12:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784085#M15144</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-11-27T12:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784086#M15145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that's a pitty, but we'll keep waiting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know where i can register for ACE software updates ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2007 13:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784086#M15145</guid>
      <dc:creator>sebastianvandijk</dc:creator>
      <dc:date>2007-11-27T13:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784087#M15146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just found out that version 2 is out, great !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, although client certificate authentication is available, i can't find how to grab / pass the user id from the certificate to the webserver ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this be done ? Or can't the certificate subject be used from within the ACE ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2008 15:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784087#M15146</guid>
      <dc:creator>sebastianvandijk</dc:creator>
      <dc:date>2008-03-18T15:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784088#M15147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, extracting values from the cert and insert into the HTTP Header did not made it in ACE2.0.&lt;/P&gt;&lt;P&gt;Next big release 3.0 should have it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2008 16:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784088#M15147</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2008-03-18T16:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784089#M15148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't exactly determine if these features have been implemented yet ?&lt;/P&gt;&lt;P&gt;And if so, does an example configuration reside somewhere on the cisco site, or can you give a hint in the right direction ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 14:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784089#M15148</guid>
      <dc:creator>sebastianvandijk</dc:creator>
      <dc:date>2010-01-12T14:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784090#M15149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like it has been implemented some time ago.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zdenek&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/ssl/guide/terminat.html#wp1169832"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/ssl/guide/terminat.html#wp1169832&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Nov 2010 11:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784090#M15149</guid>
      <dc:creator>roubicekz</dc:creator>
      <dc:date>2010-11-13T11:56:09Z</dc:date>
    </item>
    <item>
      <title>ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784091#M15150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Gilles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had a similar requirement from one of our customer that their client terminals (POS terminals) should be authenticated by the ACE which is terminating the SSL connection. Backend connections to the server is clear text.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since in a normal SSL flow the server sends the certificate to the client and the client verifies the identity of the server but in our case we need server/ACE to authenticate the client or some form of mutual authentication should be there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/ssl/guide/terminat.html#wp1117637"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/ssl/guide/terminat.html#wp1117637&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the documentation we have enabled the authgroup to enable the client authentication feature, but when we are testing the application it seems that only the front end (client to ACE) connection gets established but not the back end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have verified that if client authentication is disabled the application works fine but the ACE sends it the certificate and the client is not authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto authgroup POS&lt;/P&gt;&lt;P&gt; cert certfinal.pem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service ssl-proxy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; key POS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; cert certfinal.pem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; authgroup POS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; ssl advanced-options POS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would appreciate if you can help us out in that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhtar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2012 10:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784091#M15150</guid>
      <dc:creator>Akhtar Samo</dc:creator>
      <dc:date>2012-07-03T10:58:59Z</dc:date>
    </item>
    <item>
      <title>ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784092#M15151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Akhtar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; When doing client authentication, the ACE will request a certificate from the client.&amp;nbsp; This will be done in the SSL handshake.&amp;nbsp; If the client does not send a certificate, the handshake will fail.&amp;nbsp;&amp;nbsp; If the Client does send a certficate, then the ACE will use the certificate in the auth group to autenticate the client certificate.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your configuration, you are using cert certfinal.pem in the auth group.&amp;nbsp; This appears to be the server certificate. If that is the case, then this will not work as it is highly unlikely that the certifcate &lt;/P&gt;&lt;P&gt;cert certfinal.pem was used to sign the client certifcates.&amp;nbsp; The Authgroup should have the certificate that signed the client certs and not the server cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typicall you would see a certificate chain that would look some thing like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Root CA--signs the Intermediate CA---which signs the server or Client Certifcate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your authgroup should contain the the intermediate and root ca that signed the client certificate.&amp;nbsp; Then those client certificates must be installed on the client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2012 15:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784092#M15151</guid>
      <dc:creator>cpomeroy</dc:creator>
      <dc:date>2012-07-03T15:07:29Z</dc:date>
    </item>
    <item>
      <title>ACE SSL offloading &amp; Client certificate authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784093#M15152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per the client the certfinal.pem is generated with the combination of root certificate,&amp;nbsp; intermediate certificate (from ACE CSR) and key (generated on ACE) for CSR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On client they have uploaded intermediate certificate (from ACE CSR) because the client couldn't generate the CSR since its a POS terminal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our scenario is like given below with client authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Server)---------------clear text----------------(ACE)-----------------SSL--------------------(POS Terminals/client)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you guide us on how to move ahead ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhtar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2012 06:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-offloading-client-certificate-authentication/m-p/784093#M15152</guid>
      <dc:creator>Akhtar Samo</dc:creator>
      <dc:date>2012-07-04T06:50:03Z</dc:date>
    </item>
  </channel>
</rss>

