Forum Discussion
APM Client Certificate Validation when using policy evaluate
Dan,
First question, is there a reason you are using an iRule? Is the APM policy configured in the Virtual Server configuration?
ACCESS::policy evaluate is for evaluating a policy against an EXISTING APM session. So if there is no existing session, evaluate will return null for everything. If you are creating a session in an irule, and the policy requires client interaction there is a good chance that policy evaluation is failing.
Do you have Client Certificate Authentication enabled in the ClientSSL profile, or within APM? If you are evaluating the Client Cert at LTM with ClientSSL, you should use Client Certificate Inspection. If you are NOT performing Client Certificate Auth with the ClientSSL profile, I recommend using the On Demand Client Certificate Authentication agent.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
