Https errors for when client authentication

Hi all,
I encountered the error when i configured the web server to require client authentication. Can anyone advise?
[01/Jun/2006:15:41:08] failure (17048): HTTP3068: Error receiving request from 1
0.60.20.126 (SSL_ERROR_NO_TRUSTED_LIBSSL_CLIENT_CA: the CA that signed the clien
t certificate is not trusted locally)
Regards
Ken

The message "the CA that signed the client certificate is not trusted locally" means that the CA that signed the client certificate (i.e. the cert that 10.60.20.126 sent to the server, here) is not trusted locally (i.e. by the web server).
For SSL client auth the clients must have certs signed by some CA which is trusted by the web server. If the client has a cert issued by a known CA (like Verisign and others), those are trusted by default. I suspect here the client has a cert issued by some local CA. You need to import that CA's cert into the web server and mark it trusted.

Similar Messages

  • HTTP error for content repository

    Dear gurus,
    we defined a content repository to store images (Employee photos) in our HR instance (ECC 6). we set customizing for Sap Archive Link and "document type" (HRICOLFOTO). We followed suggestions of this link: [http://www.sd-solutions.com/documents/SDS_Employee_Photos_v4.7.html|http://www.sd-solutions.com/documents/SDS_Employee_Photos_v4.7.html].  When we try to store an image (JPG file) using OAAD transaction code we get "HTTP error: 500 Internal Server Error". Again using CSADMIN transaction code to test HTTP server assigned to content repository we get the same message. Work process trace file is attached below. Thanks for your help.
    W Tue Jan 20 09:01:06 2009
    W      *** ERROR => Failed to create new session, rc: 0x1 [itspxx.cpp   713]
    W    *** ERROR => itsp_OpenSession failed rc = 1, send icf error page [itsplxx.c    839]
    M    ***LOG W03=>  [itsplxx.c    840]
    W    *** ERROR => ipl_OpenSession returns 1(ITSPE_FAILURE) [itsplxx.c    842]
    W    *** ERROR => Raise Last error:[13 from: itspagat.cpp:820] [itsplxx.c    1180]
    W    *** ERROR => RaiseError(sapdext) ITS_P:13 [itspagat.cpp 820]
    W        *** ERROR => plugin: Unknown user agent type, not supported 'SAP Web Application Server (1.0;640)' [itspagat.cpp 819]
    W        *** ERROR => plugin: Browser verification failed rc: 1 [itspagat.cpp 750]
    W      *** ERROR => plugin: ItspAgat_InitContext failed, rc = 1 [itspxkrn.cpp 174]
    W
    W Tue Jan 20 09:01:21 2009
    W      *** ERROR => Failed to create new session, rc: 0x1 [itspxx.cpp   713]
    W    *** ERROR => itsp_OpenSession failed rc = 1, send icf error page [itsplxx.c    839]
    M    ***LOG W03=>  [itsplxx.c    840]
    W    *** ERROR => ipl_OpenSession returns 1(ITSPE_FAILURE) [itsplxx.c    842]
    W    *** ERROR => Raise Last error:[13 from: itspagat.cpp:820] [itsplxx.c    1180]
    W    *** ERROR => RaiseError(sapdext) ITS_P:13 [itspagat.cpp 820]
    W        *** ERROR => plugin: Unknown user agent type, not supported 'SAP Web Application Server (1.0;640)' [itspagat.cpp 819]
    W        *** ERROR => plugin: Browser verification failed rc: 1 [itspagat.cpp 750]
    W      *** ERROR => plugin: ItspAgat_InitContext failed, rc = 1 [itspxkrn.cpp 174]
    W      *** ERROR => Failed to create new session, rc: 0x1 [itspxx.cpp   713]
    W    *** ERROR => itsp_OpenSession failed rc = 1, send icf error page [itsplxx.c    839]
    M    ***LOG W03=>  [itsplxx.c    840]
    W    *** ERROR => ipl_OpenSession returns 1(ITSPE_FAILURE) [itsplxx.c    842]
    W    *** ERROR => Raise Last error:[13 from: itspagat.cpp:820] [itsplxx.c    1180]
    W    *** ERROR => RaiseError(sapdext) ITS_P:13 [itspagat.cpp 820]
    W        *** ERROR => plugin: Unknown user agent type, not supported 'SAP Web Application Server (1.0;640)' [itspagat.cpp 819]
    W        *** ERROR => plugin: Browser verification failed rc: 1 [itspagat.cpp 750]
    W      *** ERROR => plugin: ItspAgat_InitContext failed, rc = 1 [itspxkrn.cpp 174]
    W      *** ERROR => Failed to create new session, rc: 0x1 [itspxx.cpp   713]
    W    *** ERROR => itsp_OpenSession failed rc = 1, send icf error page [itsplxx.c    839]
    M    ***LOG W03=>  [itsplxx.c    840]
    W    *** ERROR => ipl_OpenSession returns 1(ITSPE_FAILURE) [itsplxx.c    842]
    W    *** ERROR => Raise Last error:[13 from: itspagat.cpp:820] [itsplxx.c    1180]
    W    *** ERROR => RaiseError(sapdext) ITS_P:13 [itspagat.cpp 820]
    Regards.
    :: Vittorio

    Theres a button beside CSADMIN that looks like a balance. You can use that to check... but as it is a R/3 Database repository it might not be there.
    Now, you said
    When we try to store an image (JPG file) using OAAD transaction code we get "HTTP error: 500 Internal Server Error". Again using CSADMIN transaction code to test HTTP server assigned to content repository
    How can you be calling a HTTP repository when you are actually storing the data in the R/3 Database? That doesn't make sense to me.
    Can you explain your full landscape?
    regards
    Juan

  • HTTP error 500 when trying to open Desktop

    Post Author: reneest
    CA Forum: Authentication
    I open report in infoview. Then i want to open desktop intelligence in infoview by pressin Dokument>Edit button.I get "Internal Problem invocation failed due to an HTTP error : HTTP 500 :  ".Im logged infoview as administrator.Is something wrong in my IIS server? 

    Post Author: reneest
    CA Forum: Authentication
    I open report in infoview. Then i want to open desktop intelligence in infoview by pressin Dokument>Edit button.I get "Internal Problem invocation failed due to an HTTP error : HTTP 500 :  ".Im logged infoview as administrator.Is something wrong in my IIS server? 

  • HELP! Why am I getting HTTP ERROR: 404 when trying to download CS3?

    I am trying to download CS3 Design Premium from Adobe because I lost my installation discs and need to reinstall.
    The link to download CS3 Design Premium English is broken and gives the following error:
    HTTP ERROR: 404 /support/downloads/dlm/main.jsp
    RequestURI=/support/downloads/dlm/main.jsp
    Any help out there?

    Downloads available:
    Suites and Programs:  CC 2014 | CC | CS6 | CS5.5 | CS5 | CS4 | CS3
    Acrobat:  XI, X | 9,8 | 9 standard
    Premiere Elements:  12 | 11, 10 | 9, 8, 7
    Photoshop Elements:  12 | 11, 10 | 9,8,7
    Lightroom:  5.6| 5 | 4 | 3
    Captivate:  8 | 7 | 6 | 5
    Contribute:  CS5 | CS4, CS3
    Download and installation help for Adobe links
    Download and installation help for Prodesigntools links are listed on most linked pages.  They are critical; especially steps 1, 2 and 3.  If you click a link that does not have those steps listed, open a second window using the Lightroom 3 link to see those 'Important Instructions'.

  • ODBC setup error for Oracle Client

    Hi,
    I'm trying to setup ODBC connection for my Oracle client while installing BO. Following are the steps I followed.
    1. Downloaded the Oracle Client from the link http://www.oracle.com/technetwork/database/features/instant-client/index-097480.html . From that downloaded two zip files. “Instant Client Package – Basic Lite" and “Instant Client Package – ODBC”. Extracted the Zip Files to the folder I created under C: as C:\Oracle\instantclient_11_2.
    2. Since I'm setting up in ODBC in windows 2008 64-bit R2. I was advised to install 32 bit . So in cmd prompt, from the location C:\Oracle\instantclient_11_2, ran odbc_install.
    3.Created the Environment variables as
    i) *TNS_ADMIN - C:\Oracle\instantclient_11_2*
    ii) *Oracle_Home - C:\Oracle\instantclient_11_2*
    iii) *Edited the PATH variable with ;C:\Oracle\instantclient_11_2*
    4. Created the tnsnames.ora file in C:\Oracle\instantclient_11_2. Its content are as follows.
    clarity_dev =
         (DESCRIPTION =
         (ADDRESS_LIST =
         (ADDRESS = (PROTOCOL = TCP)(HOST = claritydev.vip.its.ebay.com )(PORT = 1521))
         (CONNECT_DATA =
         (SID = clarity)
    5. From the folder %windir%\sysWOW64\odbacd32.exe, Opens ODBC Data Source Adminsitartor. In that I found my Oracle in instantclient_11_2 and added following details.
    Data Source Name : claritydev.vip.its.com
    TNS Service Name : clarity_dev
    User Id: clarity1
    When I test connect it, I get error *ORA-12154:*
    *     TNS:could not resolve the connect identifier specified*
    Could you please help, I've seen FAQs for this error, but couldn't find anything which solves. Is there any steps I'm missing? I've checked in DB properties. It uses SID not the Service Name.
    Thanks in Advance
    Sreeram

    Oh, zip files. Right. I usually use the installer.
    Try creating it yourself then and see if that does it. I don't normally use these zip files so I'm not sure if it goes somewhere else with them.

  • Error: SHA1 digest error for javax/mail/Authenticator.class

    I am using javax.mail api to sending emails.
    when I calls main method of the class to send email its works perfect, but when I imports the same class in jsp its shows me above said error.
    My email server requires authentication before sending mails.
    please guide me how to use this class in jsp .
    class code is as below :
    =========================
    import javax.mail.*;
    import javax.mail.internet.*;
    import java.util.*;
    import java.io.*;
    public class SendMailUsingAuthentication
    private static final String SMTP_HOST_NAME = "myserver.smtphost.com";
    private static final String SMTP_AUTH_USER = "myusername";
    private static final String SMTP_AUTH_PWD = "mypwd";
    private static final String emailMsgTxt = "Online Order Confirmation Message. Also include the Tracking Number.";
    private static final String emailSubjectTxt = "Order Confirmation Subject";
    private static final String emailFromAddress = "[email protected]";
    // Add List of Email address to who email needs to be sent to
    private static final String[] emailList = {"[email protected]", "[email protected]"};
    public static void main(String args[]) throws Exception
    SendMailUsingAuthentication smtpMailSender = new SendMailUsingAuthentication();
    smtpMailSender.postMail( emailList, emailSubjectTxt, emailMsgTxt, emailFromAddress);
    System.out.println("Sucessfully Sent mail to All Users");
    public void postMail( String recipients[ ], String subject,
    String message , String from) throws MessagingException
    boolean debug = false;
    //Set the host smtp address
    Properties props = new Properties();
    props.put("mail.smtp.host", SMTP_HOST_NAME);
    props.put("mail.smtp.auth", "true");
    Authenticator auth = new SMTPAuthenticator();
    Session session = Session.getDefaultInstance(props, auth);
    session.setDebug(debug);
    // create a message
    Message msg = new MimeMessage(session);
    // set the from and to address
    InternetAddress addressFrom = new InternetAddress(from);
    msg.setFrom(addressFrom);
    InternetAddress[] addressTo = new InternetAddress[recipients.length];
    for (int i = 0; i < recipients.length; i++)
    addressTo[i] = new InternetAddress(recipients);
    msg.setRecipients(Message.RecipientType.TO, addressTo);
    // Setting the Subject and Content Type
    msg.setSubject(subject);
    msg.setContent(message, "text/plain");
    Transport.send(msg);
    * SimpleAuthenticator is used to do simple authentication
    * when the SMTP server requires it.
    private class SMTPAuthenticator extends javax.mail.Authenticator
    public PasswordAuthentication getPasswordAuthentication()
    String username = SMTP_AUTH_USER;
    String password = SMTP_AUTH_PWD;
    return new PasswordAuthentication(username, password);

    Find all the jar files under Tomcat's installation directory and all the jar files in the jre/lib/ext directory.
    Make sure only one of them includes javax.mail.* classes.
    Note that setting CLASSPATH to a directory does not cause all jar files in that directory to be loaded.
    Finally, make sure Eclipse isn't copying the class files out of mail.jar and packaging them with your
    application.

  • Cluster-related error for remote client

              Hello,
              I am getting the following error when running a remote stand-alone client that attempts to access an entity bean that is running within WLS6.1sp2:
              java.lang.NullPointerException
              at weblogic.rmi.cluster.WeightBasedReplicaHandler.chooseReplica(WeightBasedReplicaHandler.java:65)
              at weblogic.rmi.cluster.BasicReplicaHandler.loadBalance(BasicReplicaHandler.java:258)
              at weblogic.rmi.cluster.ReplicaAwareRemoteRef.invoke(ReplicaAwareRemoteRef.java:223)
              at weblogic.rmi.internal.ProxyStub.invoke(ProxyStub.java:35)
              at $Proxy1.findByPrimaryKey(Unknown Source)
              at ProductClient.main(ProductClient.java:40)
              We are not using clustering. The standalone client is using "copied" jars such as weblogic.jar on a win2000 pc. The error happens whether we run WLS on unix or on win2000.
              Any thoughts on how to avoid this problem?
              Thanks for any help,
              Clint Prouty
              DST Systems
              

    As i mentioned earlier NPE is our problem.
              Pls try SP3 and if that doesn't solve, follow up with support.
              Kumar
              Clint Prouty wrote:
              > Hi Rajesh,
              >
              > Yes I do have the clustering license key in my license.bea file.
              > The error happens even if the client is running on the same
              > win200O PC as WLS. The error I listed comes from the client program, so I am
              > not sure how the license would come into play.
              >
              > Thanks,
              >
              > Clint
              >
              > Rajesh Mirchandani <[email protected]> wrote:
              >
              >>Do you have a clustering license key in your license.bea file ? It seems
              >>that we are looking for the cluster license even though you are not
              >>using clustering.
              >>
              >>Put the key in and see if it helps.
              >>
              >>Kumar Allamraju wrote:
              >>
              >>
              >>>you should report this problem to [email protected]
              >>>
              >>>I'm not sure if it's a known issue in SP2 and fixed in SP3. It's worth
              >>>trying SP3.
              >>>
              >>>--
              >>>Kumar
              >>>
              >>>Clint Prouty wrote:
              >>>
              >>>
              >>>>Hello,
              >>>>
              >>>>I am getting the following error when running a remote stand-alone
              >>>>
              >>client that attempts to access an entity bean that is running within
              >>WLS6.1sp2:
              >>
              >>>>java.lang.NullPointerException
              >>>> at weblogic.rmi.cluster.WeightBasedReplicaHandler.chooseReplica(WeightBasedReplicaHandler.java:65)
              >>>> at weblogic.rmi.cluster.BasicReplicaHandler.loadBalance(BasicReplicaHandler.java:258)
              >>>> at weblogic.rmi.cluster.ReplicaAwareRemoteRef.invoke(ReplicaAwareRemoteRef.java:223)
              >>>> at weblogic.rmi.internal.ProxyStub.invoke(ProxyStub.java:35)
              >>>> at $Proxy1.findByPrimaryKey(Unknown Source)
              >>>> at ProductClient.main(ProductClient.java:40)
              >>>>
              >>>>We are not using clustering. The standalone client is using "copied"
              >>>>
              >>jars such as weblogic.jar on a win2000 pc. The error happens whether
              >>we run WLS on unix or on win2000.
              >>
              >>>>Any thoughts on how to avoid this problem?
              >>>>
              >>>>Thanks for any help,
              >>>>
              >>>>Clint Prouty
              >>>>DST Systems
              >>>>
              >>>>
              >>--
              >>Rajesh Mirchandani
              >>Developer Relations Engineer
              >>BEA Support
              >>
              >>
              >>
              >
              

  • Http error 404 when accessing facebook pages

    HI there
    I have read a few of the previous help requests and  tried to turn my mobile netwok off and on and a hard reboot, but I still can't access facebook pages via an email link.  I get a message about a reply say to a comment and when I click through I just get the above error message.
    I'd be very grateful if someone could send me suggestions to resolve this.  In simple terms if poss as although I'm fairly computer literate some of the ideas have gone over my head!
    I have a blackberry curve 8520.  I use virgin/orange.  Not sure if you need this v5.0.0.681  Facebook is version 2.0.0.58
    Thank you

    Hi dear BB User
    I use BB 9900 since 1 Month and i really have alot of Problem and this is one of the problem that you said but i can help you out with this.
    first if you use Wi Fi and in the same time you need your Phone network also with that otherwise it is not gonna work and if you turn off your phone network so you can do nothing and be carefull dont trap when you do something and you are connected with Wi Fi and in real cost you also in Phone NEtwork i hope it is hope full for you....

  • Tracking status in CRM-online of MUP in error for MSA clients

    Hi,
    We are using the Upgrade console to distribute MSA application updates via the middleware.
    When these are in error, a status entry and log file errors are put back into the CRM-online tables SMOGSYSMP and SMOGSYSMON.
    Has anyone written any ABAP's to interpret these tables into a more readable format?
    Thanks,
    Graham

    Hi Simran08,
    According to your description, you fail to add your report to CRM due to the custom code. Right?
    In this scenario, based on my knowledge, I find two issues in your custom code.
    You pass the array Items as argument to the function. This array is from the LookupSet() function. However, it returns an concatenated string with commas. When you convert it into decimal, it will throw error.
    In your For Each loop part, we should follow the format below:
    For Each element In group
    [statements]
    [Exit For]
    [statements]
    Next [element]
    It seems you miss Item after Next.
    If you still have any question, please feel free to ask.
    Best Regards,
    Simon Hou

  • HTTP Error 400 when trying to view a report

    We use MS Dynamics CRM 2013 SP 1 Rollup 2 on Windows Server 2012 and separate SQL Server 2012 on Windows Server 2012 as well.
    Only one user is affected by the issue. Other users with exactly the same Security Roles in CRM and Groups in Active Directory are not affected whatsoever. I've read that this issue may occur if the user is a member of too many groups in AD but in this case
    it's only 7 groups.
    This is the second time the issue occures with the same user. The first time it was resolved by deactivating/activating the user in AD. Not this time, unfortunatly.
    I have no more ideas what to try and where to look. Help would be greatly appreciated.

    Hi,
         Have you checked the DNS entry for this particular user? Few things you can try from following link:
    http://www.getnetgoing.com/HTTP-400.html
    Hope this helps.
    Minal Dahiya
    blog : http://minaldahiya.blogspot.com.au/
    If this post answers your question, please click "Mark As Answer" on the post and "Vote as Helpful"

  • Initial configuration of ACS 5.1 for EAP authentication for Wireless clients

    Hi,
    I have set-up with below devices :
    Wireless LAN controller 5508
    LAP 3302i
    and ACS 5.1
    since i am new in ACS 5.1 configuration , I need so information to go ahead to configure ACS 5.1.
    which EAP method to use for wireless client authentication ? what is the best practice ?
    I have gone through some cisco documents and it shows that best practice is to configure PEAP but for the same , I need to install certificate in ACS server as well in client PC. is that so ?
    I have no clear picture for this certificate ?
    from where i can get this certificate or do i need to purchase this certificate separately from cisco. how to install it in ACS server ?
    I will be obliged to get atleast initial configuration for ACS 5.1 to enable the EAP method,
    I need GUI based initial configuration for ACS 5.1
    This mentioned ACS 5.1 is installed on ACS 1121 hardware appliance.

    Hi,
    which EAP method to use for wireless client authentication ? what is the best practice ?
    -> I would advise the most widely spread EAP method, which has the best ratio security/easy to deploy: PEAP with MSCHAPv2, which is available by default by all windows machines.
    I  have gone through some cisco documents and it shows that best practice  is to configure PEAP but for the same , I need to install certificate in  ACS server as well in client PC. is that so ?
    -> You will always need to install a server certificate, however, there is no need for client certificate because the authentication is based on the MSCHAP credentials exchange, not certificate based. The only requirement on the client regarding certificates is the following.
    If you want to validate the server certificate, you have to install the server certificate under the trusted CAs of the clients.
    If you do not require to trust the server certificate, you can simply disable the option of server certificate validation.
    I have no clear picture for this certificate ?
    from  where i can get this certificate or do i need to purchase this  certificate separately from cisco. how to install it in ACS server ?
    -> The server certificate can be a simple self signed certificate that you generate and install on the ACS GUI.
    Please feel free to follow this step-by-step guide on
    PEAP under Unified Wireless Networks with ACS 5.1 and Windows 2003 Server:
    http://www.cisco.com/en/US/partner/products/ps10315/products_configuration_example09186a0080b4cdb9.shtml or in pdf
    http://www.cisco.com/image/gif/paws/112175/acs51-peap-deployment-00.pdf.
    HTH,
    Tiago
    If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

  • Tomcat repeatedly prompts for client authentication w/ IIS as web server

    Team,
    We have an IIS 6 / Tomcat configuration using the Apache supplied ISAPI redirector. The client application is an Applet that is using signed Jars.
    The environment has been configured and communication is happening correctly between IIS and Tomcat, and the client applet is functioning properly.
    Client Authentication (using Active Directory) is turned on in IIS and is authenticating Users correctly.
    The only issue is that the Users are being prompted multiple times (throughout the same session) for their client authentication. The Applet communicates to the server through a single servlet.
    This multiple prompting is unacceptable, because if a User does not notice that they have had their cert requested again (sometimes it pops - up minimized, or they are working to fast so it ends up behind the applet), the communication to the servlet is severed and the User ends up with some very bad results.
    My question is: How can I make Tomcat stop authenticating clients? We have ONLY allowed the AJP connector to be open, and have set "tomcatAuthenticate" to false so that the RemoteUser and Principle are passed correctly from IIS.
    I have attempted "socket_keepalive" in the workers.properties file and even clientAuth=false on the AJP connector (which I believe is not a valid parameter).
    Does anyone have an idea of what I should do next? I have not attempted to import my client certificate into Tomcat's keystore yet, and am hoping that that is not the solution.

    From the info above I see you are trying to publish over HTTPS?
    BUT the request doesn't seem to be for HTTPS.
    Request: GET http://test.mm.com/ 
    Filter information: Req ID: 11cb9306; Compression: client=Yes, server=No, compress rate=0% decompress
    rate=0% 
    Protocol: http 
    Please try to access as https://yourdomainserver.com
    let me know, how it goes, will be happy to help!

  • HTTP Error 501 with SOAP Sender channel

    Hello,
    i've am simple Question:
    I want to call the following SAP XI SOAP Sender channel "MySoapSenderChannel":
    XI-Parameters:
    namespace: <myInterfaceNamespace>
    Interface:   <myAsynchInterface>
    QoS: Exactly Once in Order
    Queue: MY_QUEUE
    We do not care about the Response - so the processing is asynchron.
    Thus my interface mapping maps to asynch interfaces. The desitnation
    is an ABAP Proxy. The configuration has been done and tested.
    Here my question:
    according the documentation, the URL has the following syntax:
    http://host:port/XISOAPAdapter/MessageServlet?channel=party:service:channel.
    In our case:
    http://<myHost>:8002/XISOAPAdapter/MessageServlet?channel=:MyService:MySoapSenderChannel.
    But when i generate a WSDL for the interface out of the Configuration, the address is:
    <soap:address location="http://<myHost>:8002/sap/xi/engine?type=entry&amp;version=3.0&amp;Sender.Service=MyService&amp;Interface=...
    and so forth.
    But was is the difference between these 2 possibilities?
    Why do i get HTTP Error 501 when i use the URL from the documentation (the first one)?
    Thanx in advance
    Gunnar

    Gunnar,
    I will suggest you to go through it once to check all your connection.
    /people/vijaya.kumari2/blog/2006/01/26/how-do-you-activate-abap-proxies
    Regards,
    Sarvesh

  • SWN_SELSEN HTTP ERROR 500

    Hello,
    Does anybody know how to solve following issue ...
    We have sheduled swn_selsen to send notifications to outlook.
    Now we receive error HTTP 500.
    Error when creating message
    USER .... unable to determine telephone number
    HTTP  error 500 when creating message.
    => the message with the telephone is not relevant we are not using sms and there is a telephone present in the user settings.
    Thank you very much for your help.
    Best regards,
    Daisy Heremans

    Hello Daisy,
    The telephone is a red herring, ignore it. Sounds like you have not activated all necessary services, have a look under prerequisites in the online help:
    http://help.sap.com/saphelp_nw70ehp1/helpdata/en/ee/a80b404b2b1e07e10000000a1550b0/frameset.htm
    Cheers,
    Mike

  • Cisco CSS Client Authentication

    I have a few questions in this regard..
    1.) Is it possible to use self signed certs for the client authentication, baring in mind you need to point the CSS to the CRL?
    2.) I need to run around 20 different VIP's (probably on the same IP but with different tcp ports), all requiring their own individual certificate for client auth. Is there a limit to the number of client authentication certificates I can load on a 11501S device?
    3.) Can someone provide me with a working configuration example for client authentication on a CSS?

    client authentication means the CSS will request the client to send its own certificate and we will check its validity with the configured CA and configured CRL.
    It has nothing to do with the CSS certificate.
    So, you could have a self signed certificate on the CSS. That doesn't change anything for client authentication.
    The same IP thing is probably not a good thing if you want to assign the certificate to different domain.
    A dns request will only return an ip address and no port.
    So you may end up with all requests going to the same ip and port 443.
    I think the limit is 256 ssl-proxy server.
    Check config guide for assistance :
    http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v7.50/configuration/ssl/guide/terminat.html#wp999318
    Gilles.

Maybe you are looking for