NetScaler crashes if an ssl certificate with SNI is unbound fron an active ssl vserver
book
Article ID: CTX231416
calendar_today
Updated On:
Description
NetScaler in HA pair, the primary device crashed and failed over to the secondary after generating core file.
The NetScaler appliance becomes unresponsive if after an SNI handshake is complete, an HTTP/1.1 request is received and the SNI certificate is unbound from the virtual server simultaneously.
Resolution
This has been identified as abnormal behavior in the firmware and the fix for this issue has been included in the firmware release for 11.1 57.13,12.0 57.24 and 12.1 48.13.
The description for the issue in the release notes:
Feature: SSL (697789)
Problem Cause
When a certificate with SNI is unbound from an ssl vserver that has active connections/transactions, it will cause the NS to crash and generate core files.
Issue/Introduction
In an active ssl vserver has active ongoing connections and the ssl cert bound to it is unbound, it will cause the crash on the NS
Was this article helpful?
thumb_up
Yes
thumb_down
No