New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 813663 link

Starred by 2 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug



Sign in to add a comment

ChromeOS issue: Unable to select a client cert on F5 VPN app

Project Member Reported by soushi@chromium.org, Feb 19 2018

Issue description

Chrome Version: 65.0.3225.65 (Official Build) beta (32 bit)
Platform: 10323.30.0 (Official Build) beta-channel veyron_minnie
Firmware: Google_Veyron_Minnie.6588.237.0
ARC: 4598704

Description:
Unable to show the client cert selection dialog on F5 Access (Chrome app).

Steps to reproduce: 
1. Install F5 Access via Admin Console (Allow access to enterprise API: Enabled)
2. Login as a user
3. Launch F5 Access
4. Click on '+ (Add Configuration)' button to create a new VPN connection
5. Check 'Client Certificate' checkbox to use client cert auth
6. Click on 'SELECT CERTIFICATE' button, but it doesn't show the client cert selection dialog

Current Behavior / Reproduction: 
A client cert selection dialog doesn't show up on F5 Access.

Expected Behavior: 
After clicking 'SELECT CERTIFICATE' button (step #6), a client cert selection dialog should show up.


 
Screenshot 2018-02-20 at 08.39.38.png
57.0 KB View Download

Comment 1 by est...@chromium.org, Feb 22 2018

Owner: emaxx@chromium.org
Assigning to emaxx for triage. It seems likely that this is a problem with the F5 app, not on our end.
Components: Platform>Apps>ARC

Comment 3 by emaxx@chromium.org, Feb 27 2018

Components: -Platform>Apps>ARC Platform>Apps>API
The dialog is intentionally not shown whenever there's no certificate to select from.

soushi@: Is there a valid certificate available when the repro step #6 is performed?

As a side note, we had a change recently in the API implementation that is in some cases reducing the set of candidates for the cert selection dialog (crbug.com/763746#c19); however, unless there was some bug introduced, that could only affect certificates which were unavailable for signing anyway.

Comment 4 by avkuli...@gmail.com, Feb 27 2018

Are the client certificates using RSA keys or elliptic curve keys? F5 VPN app does not currently support elliptic curve keys for client certificate authentication.
Status: Assigned (was: Untriaged)
This bug has an owner, thus, it's been triaged. Changing status to "assigned".

Sign in to add a comment