Hi,
you can try the following:
In TLS Server Profile set "
Request client authentication" = "on", "
Require client authentication" = "off" and "
Validate client certificate" = "off".
Then drag an AAA action to processing policy flow and set authentication to "
Validate TLS certificate from connection peer" and select the correct validation credential config from the drop-down menu. Now you should be able to catch the certificate errors using error rule and create a custom error response back to the consumers.
------------------------------
Hermanni Pernaa
------------------------------