<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS TO HTTPS rewrite error with Wilcard Cert in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/https-to-https-rewrite-error-with-wilcard-cert/m-p/1835212#M36097</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I have a wildcard cert installed on my ACE and a HTTP redirect for any http traffic.&amp;nbsp; The redirect works fine for all http traffic and HTTPS traffic.&amp;nbsp; I am recieving an error when users try to connect to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://domain.com"&gt;https://domain.com&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp; If they connect to &lt;A href="Https://www.domain.com" target="_blank"&gt;Https://www.domain.com&lt;/A&gt;, &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://mail.domain.com"&gt;https://mail.domain.com&lt;/A&gt;&lt;SPAN&gt;, etc. it works fine.&amp;nbsp; I only get errors when the www or any specific host name is left off and https request.&amp;nbsp; I am receiving the error the domain does not mach the cert.&amp;nbsp; The cert is configured for *.domian.com.&amp;nbsp; Below is my config.&amp;nbsp; Any Ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver redirect HTTPS-REDIR&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/"&gt;https://%h%p&lt;/A&gt;&lt;SPAN&gt; 301&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver redirect HTTPS-REDIR-domain&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.domain.com"&gt;https://www.domain.com&lt;/A&gt;&lt;SPAN&gt; 301&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host WEBSERVER-01&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.50.20.132&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host WEBSERVER-02&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.50.20.133&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type modify http ADD-HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl url rewrite location ".*"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host ALGINE-SERVERFARM-80&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe PING&lt;/P&gt;&lt;P&gt;&amp;nbsp; fail-on-all&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver WEBSERVER-01 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver WEBSERVER-02 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm redirect HTTP-HTTPS-REDIR&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Redirection from Port 80 to 443&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver HTTPS-REDIR-domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service domain-domain-COM&lt;/P&gt;&lt;P&gt;&amp;nbsp; key *.domain.com-KEY-2011&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert *-domain-com.cer&lt;/P&gt;&lt;P&gt;&amp;nbsp; chaingroup TEST-CHAIN&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl advanced-options PARAM-RSA-SSL1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky http-cookie ALG-LB ALG-COOKIE-01&lt;/P&gt;&lt;P&gt;&amp;nbsp; cookie insert&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 120&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm DOMAIN-SERVERFARM-80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any CM-domain-COM-http&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 11.11.11.11 tcp eq www&lt;/P&gt;&lt;P&gt;class-map match-any CM-domain-COM-https&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 11.11.11.11 tcp eq https&lt;/P&gt;&lt;P&gt;class-map match-any CM-TEST-MAP&lt;/P&gt;&lt;P&gt;class-map type management match-any remote_access&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match protocol xml-https any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 match protocol icmp any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4 match protocol telnet any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 match protocol ssh any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 6 match protocol http any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 7 match protocol https any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8 match protocol snmp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match remote_mgmt_allow_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class remote_access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match CM-domain-COM&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm ALG-COOKIE-01&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match CM-domain-COM-http&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm HTTP-HTTPS-REDIR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match INT-VLAN229-VIPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; class CM-domain-COM-http&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy CM-domain-COM-http&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options HTTP-OPTIONS_1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP-CONN-OPTIONS&lt;/P&gt;&lt;P&gt;&amp;nbsp; class CM-domain-COM-https&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy CM-domain-COM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options HTTP-OPTIONS_1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server domain-domain-COM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP-CONN-OPTIONS&lt;/P&gt;</description>
    <pubDate>Sat, 21 Jan 2012 00:51:45 GMT</pubDate>
    <dc:creator>cbregeripr</dc:creator>
    <dc:date>2012-01-21T00:51:45Z</dc:date>
    <item>
      <title>HTTPS TO HTTPS rewrite error with Wilcard Cert</title>
      <link>https://community.cisco.com/t5/application-networking/https-to-https-rewrite-error-with-wilcard-cert/m-p/1835212#M36097</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have a wildcard cert installed on my ACE and a HTTP redirect for any http traffic.&amp;nbsp; The redirect works fine for all http traffic and HTTPS traffic.&amp;nbsp; I am recieving an error when users try to connect to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://domain.com"&gt;https://domain.com&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp; If they connect to &lt;A href="Https://www.domain.com" target="_blank"&gt;Https://www.domain.com&lt;/A&gt;, &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://mail.domain.com"&gt;https://mail.domain.com&lt;/A&gt;&lt;SPAN&gt;, etc. it works fine.&amp;nbsp; I only get errors when the www or any specific host name is left off and https request.&amp;nbsp; I am receiving the error the domain does not mach the cert.&amp;nbsp; The cert is configured for *.domian.com.&amp;nbsp; Below is my config.&amp;nbsp; Any Ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver redirect HTTPS-REDIR&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/"&gt;https://%h%p&lt;/A&gt;&lt;SPAN&gt; 301&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver redirect HTTPS-REDIR-domain&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.domain.com"&gt;https://www.domain.com&lt;/A&gt;&lt;SPAN&gt; 301&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host WEBSERVER-01&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.50.20.132&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host WEBSERVER-02&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.50.20.133&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type modify http ADD-HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl url rewrite location ".*"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host ALGINE-SERVERFARM-80&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe PING&lt;/P&gt;&lt;P&gt;&amp;nbsp; fail-on-all&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver WEBSERVER-01 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver WEBSERVER-02 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm redirect HTTP-HTTPS-REDIR&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Redirection from Port 80 to 443&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver HTTPS-REDIR-domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service domain-domain-COM&lt;/P&gt;&lt;P&gt;&amp;nbsp; key *.domain.com-KEY-2011&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert *-domain-com.cer&lt;/P&gt;&lt;P&gt;&amp;nbsp; chaingroup TEST-CHAIN&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl advanced-options PARAM-RSA-SSL1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky http-cookie ALG-LB ALG-COOKIE-01&lt;/P&gt;&lt;P&gt;&amp;nbsp; cookie insert&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 120&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm DOMAIN-SERVERFARM-80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any CM-domain-COM-http&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 11.11.11.11 tcp eq www&lt;/P&gt;&lt;P&gt;class-map match-any CM-domain-COM-https&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 11.11.11.11 tcp eq https&lt;/P&gt;&lt;P&gt;class-map match-any CM-TEST-MAP&lt;/P&gt;&lt;P&gt;class-map type management match-any remote_access&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match protocol xml-https any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 match protocol icmp any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4 match protocol telnet any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 match protocol ssh any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 6 match protocol http any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 7 match protocol https any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8 match protocol snmp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match remote_mgmt_allow_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class remote_access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match CM-domain-COM&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm ALG-COOKIE-01&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match CM-domain-COM-http&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm HTTP-HTTPS-REDIR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match INT-VLAN229-VIPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; class CM-domain-COM-http&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy CM-domain-COM-http&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options HTTP-OPTIONS_1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP-CONN-OPTIONS&lt;/P&gt;&lt;P&gt;&amp;nbsp; class CM-domain-COM-https&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy CM-domain-COM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options HTTP-OPTIONS_1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server domain-domain-COM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP-CONN-OPTIONS&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2012 00:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/https-to-https-rewrite-error-with-wilcard-cert/m-p/1835212#M36097</guid>
      <dc:creator>cbregeripr</dc:creator>
      <dc:date>2012-01-21T00:51:45Z</dc:date>
    </item>
    <item>
      <title>HTTPS TO HTTPS rewrite error with Wilcard Cert</title>
      <link>https://community.cisco.com/t5/application-networking/https-to-https-rewrite-error-with-wilcard-cert/m-p/1835213#M36098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris&lt;/P&gt;&lt;P&gt;ACE can't cause such type of problems, as this check is a simple check done on browser side.&lt;/P&gt;&lt;P&gt;The problem seems to be that wilcard certificate for *.domain.net matchs e.g. these domains : a.domain.net, b.domain.net, c.domain.net but doesn't match domain.net&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://wiki.cacert.org/WildcardCertificates"&gt;http://wiki.cacert.org/WildcardCertificates&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 09:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/https-to-https-rewrite-error-with-wilcard-cert/m-p/1835213#M36098</guid>
      <dc:creator>Borys Berlog</dc:creator>
      <dc:date>2012-01-23T09:19:12Z</dc:date>
    </item>
  </channel>
</rss>

