Forum Discussion
APM for banner and cert
When implementing the "require" parameter in ClientSSL profiles, a significant limitation exists: connections with missing or invalid certificates are terminated immediately without providing any diagnostic information or user feedback. This creates a poor user experience and complicates troubleshooting.
A more effective approach is to maintain the "require" parameter in your ClientSSL profile and use "On-Demand Cert Auth" instead of "Client Cert Inspection" within your APM policy.
This configuration allows certificate validation failures to be handled gracefully within the APM policy, enabling customized user feedback and remediation paths.
While Message Box would do the job , if you are familiar with JS, consider using the Advanced Customization feature in your APM policy to create the banner.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com