SSL handshake failure due to unsupported client certificate bit size

SSL handshake failure due to unsupported client certificate bit size

book

Article ID: CTX339948

calendar_today

Updated On:

Description

From the trace after SSL handshake, VIP is sending reset with code 9811

image.png

Resolution

Customer fixed the certificate issue and now able to connect the VPN

Problem Cause

Issue is due to non supported client certificate bit size of 2056 bit.

We do not support if it is not multiple of 512 bits
ERROR: Certificate with key size (modulus) that is not multiple of 512 bits is not supported

image.png