Forum Discussion

sunilmoudgalya_'s avatar
sunilmoudgalya_
Icon for Nimbostratus rankNimbostratus
Jun 22, 2015

ADFS proxy not working

We have F5 hardware load balancer which do the load balancing job for ADFS proxy server requests with certificates configured in F5, We have replaced SHA 1 certiifcates with SHA2 (sha256)certificates both on servers & as well in F5 post that external users are not able to login to ADFS relying party applicatons whereas internal one's working fine

 

Internal request---F5(No Certificate)---ADFS 3.0 (Hosted 2012 R2) servers External request--F5(Certificate)---ADFS proxy servers (Hosted on 2012 R2 servers)---ADFS servers

 

In ADFS proxy servers, we are finding many CIPHER errors which came after certificate renewal. Post roll back to old certificate errors are gone

 

Currently on F5 it is configured with default Cipher settings, Can someone have any idea whether it require any changes related to CIpher suite

 

If i change the Cipher suite will it impact other VIP's

 

Log Name: System

 

Source : Schannel

 

Event ID: 36888

 

Time : 6/15/2015 10.01 AM

 

Level : Error

 

User : System

 

Computer : abc

 

Description: A fatal alert was generated and sent to remote endpoint. This may result in termination of connection. The TLS protocol defined fatal error code is 40. The windows Schannel error state is 1205

 

Log Name: System

 

Source : Schannel

 

Event ID: 36874

 

Time : 6/15/2015 10.01 AM

 

Level : Error

 

User : System

 

Computer : abc

 

Description: An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed

 

7 Replies

  • i have some experience with windows server not liking TLS1.2 yet, you could try with a cipher like !TLSv1_2:DEFAULT

     

  • we are in the process of configuring servers for ADFS and i came across this issue last week. our ADFS proxies sit behind a couple of units running 11.6 (i had to disable TLS1.2 in the server SSL profile in order to get things working), while our internal ADFS servers sit behind a couple of units running 10.2.3 (no issues).

     

  • 10.2.3 supports a limited number of ciphers with TLS1.2, it might be those don't cause issues.

     

  • We have 11.4.1 on both external (proxy connection) and internal F5. The problem is only on the external one. If we connect an ADFS proxy directly to internet the problem goes away. Can it have something to to with the SNI part? That is only used in the proxy configuration. The communication between proxy and internal ADFS (through F5) is not SNI configured in my setup.

     

    • boneyard's avatar
      boneyard
      Icon for MVP rankMVP
      are you the same person as the original poster? if not it might be wise to start a new question with your details.
  • We have 11.4.1 on both external (proxy connection) and internal F5. The problem is only on the external one. If we connect an ADFS proxy directly to internet the problem goes away. Can it have something to to with the SNI part? That is only used in the proxy configuration. The communication between proxy and internal ADFS (through F5) is not SNI configured in my setup.

     

    • boneyard's avatar
      boneyard
      Icon for MVP rankMVP
      are you the same person as the original poster? if not it might be wise to start a new question with your details.