Forum Discussion
APM: selecting clientssl profile based on client certificate
Hi All,
I am using a self signed CA to provide client authentication for APM.
We have recently swapped to a new CA and need to retire the old CA.
The issue I have is that in order to cutover from the old CA to the new CA, both CA's need to authenticate clients in the APM module (On Demand Certificate Authentication) at the same time.
The flow I would like to create would look something like this: - On the on demand cert auth in APM, the CA issuer of the client (user certificate) is identified. This irule variable should do the trick: [X509::issuer [SSL::cert 0]] - Based on the result the clientssl profile, including CRL, for the associated CA is used for authentication. This will mean applying to the LTM virtual server
To complicate matters I have SNI enabled on the virtual servers.
I have seen irules that could be reworked if this was an ltm only issue, for example https://devcentral.f5.com/questions/modifying-http-header-on-the-basis-of-ssl-certificate and https://devcentral.f5.com/questions/client-ssl-cert-irule could be modified, however APM is requesting and validating the client certificate so linking that back to the ltm policy is slightly harder (Apple devices connecting so doing the auth on the ltm is an unpleasant user journey - Don't want users getting prompted for a certificate constantly). Also irule prompts like CLIENTSSL_CLIENTCERT and CLIENTSSL_HANDSHAKE do not respond with the [X509::issuer [SSL::cert 0]] variable in ltm. These are only picked up in the APM, which puts the cart before the horse so to speak as ltm sets these before apm is envoked as far as I can tell.
Has anyone on the forum had to migrate to a new user CA before with APM and how did you do it?
BR,
Ben.
3 Replies
- Renato
Altostratus
You can concatenate both the CA bundles in a single file and use it as your trusted/advertised CA. Doing it the ssl profile will authenticate certificates issued by both the CAs.
- Ben_Thornton_10
Nimbostratus
Thanks Renato - woke up this morning after posting this thinking along the same lines.
Will give it a go and let you know if that fixes it.
Ben.
- Ben_Thornton_10
Nimbostratus
Just tested and this fix works.
Thanks all.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com