Forum Discussion
soymanue
Nimbostratus
Oct 29, 2012Access Policy Manager OnDemand Certificate Authentication
Can the APM authenticate with a certificate without providing the user password?
We have Widows AD and Windows CA. We want to distribute a profile to iOS devices. It is possible to configure remotely the username and to send the certificate. But we can't send the password.
So, we would like to check against the Internal CA that the certificate corresponds to a user. But we don't want to ask for the AD user's password.
Is it possible?
1 Reply
- Yes, of course. You can configure APM to do OnDemand client cert, it will require a user to present a cert. Then you run OCSP check against your internal CA, and if it passes, allow the session to proceed.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects