In a typical SSL transaction, the client that is connecting to a server over a secure connection checks the validity of the server. To do so, it checks the server's certificate before initiating the SSL transaction. Sometimes, however, you might want to configure the server to authenticate the client that is connecting to it.
Note: From release 13.0 build 41.x, the NetScaler appliance supports certificate request messages that are fragmented into more than one record if the total size is within 32 KB. Earlier, the maximum supported size was 16 KB and fragmentation was not supported.
With client authentication enabled on an SSL virtual server, the NetScaler appliance asks for the client certificate during the SSL handshake. The appliance checks the certificate presented by the client for normal constraints, such as the issuer signature and expiration date.
From release 13.1 build 42.x, the NetScaler appliance supports cross-signed certificate validation. That is, if a certificate is signed by multiple issuers, the validation passes if there is at least one valid path to the root certificate. Earlier, if one of the certificates in the certificate chain was cross-signed and had multiple paths to the root certificate, the ADC appliance only checked for one path. And if that path was not valid, the validation failed.
For the appliance to verify issuer signatures, the certificate of the CA that issued the client certificate must be:
If the certificate is valid, the appliance allows the client to access all secure resources. But if the certificate is invalid, the appliance drops the client request during the SSL handshake.
The appliance verifies the client certificate by first forming a chain of certificates, starting with the client certificate, and ending with the root CA certificate for the client (for example, Verisign). The root CA certificate might contain one or more intermediate CA certificates (if the root CA does not directly issue the client certificate).
Before you enable client authentication on the NetScaler appliance, make sure that a valid client certificate is installed on the client. Then, enable client authentication for the virtual server that handles the transactions. Finally, bind the certificate of the CA that issued the client certificate to the virtual server on the appliance.
Note: A NetScaler MPX appliance supports a certificate-key pair size from 512 bits to 4096 bits. The certificate must be signed by using one of the following hash algorithms:
-
MD5
-
SHA-1
-
SHA-224
-
SHA-256
-
SHA-384
-
SHA-512
On an SDX appliance, if an SSL chip is assigned to a VPX instance, the certificate-key pair size support of an MPX appliance applies. Otherwise, the normal certificate-key pair size support of a VPX instance applies.
A NetScaler virtual appliance (VPX instance) supports certificates of at least 512 bits, up to the following sizes:
-
4096-bit server certificate on the virtual server
-
4096-bit client certificate on the service
-
4096-bit CA certificate
-
4096-bit certificate on the physical server
From release 13.1 build 17.x, all NetScaler platforms support certificates that are signed using the RSASSA-PSS algorithms. These algorithms are supported in the X.509 certificate path validation. The following table shows the RSASSA-PSS parameter sets supported by the NetScaler appliance.
| Public Key OID |
Mask Generation Function (MGF) |
MGF Digest Function |
Signature Digest Function |
Salt Length |
| rsaEncryption |
MGF1 |
SHA-256 |
SHA-256 |
32 bytes |
| rsaEncryption |
MGF1 |
SHA-384 |
SHA-384 |
48 bytes |
| rsaEncryption |
MGF1 |
SHA-512 |
SHA-512 |
64 bytes |
Note: From release 13.0 build 79.x, client authentication with 4096-bit RSA client certificate is supported during an SSL handshake on the VPX platform.
Notes: