NetScaler crashes if an ssl certificate with SNI is unbound fron an active ssl vserver

NetScaler crashes if an ssl certificate with SNI is unbound fron an active ssl vserver

book

Article ID: CTX231416

calendar_today

Updated On:

Description

NetScaler in HA pair, the primary device crashed and failed over to the secondary after generating core file.
The NetScaler appliance becomes unresponsive if after an SNI handshake is complete, an HTTP/1.1 request is received and the SNI certificate is unbound from the virtual server simultaneously. 

Resolution

This has been identified as abnormal behavior in the firmware and the fix for this issue has been included in the firmware release for 11.1 57.13,12.0 57.24 and 12.1 48.13.

The description for the issue in the release notes:
Feature: SSL (697789)
 

Problem Cause

When a certificate with SNI is unbound from an ssl vserver that has active connections/transactions, it will cause the NS to crash and generate core files.
 

Issue/Introduction

In an active ssl vserver has active ongoing connections and the ssl cert bound to it is unbound, it will cause the crash on the NS