Forum Discussion
AWAF Access Profile, missing a configurable JWKS URL - RFE
The AWAF Access Profile functionality (introduced in 17.5) is potentially a great feature, but IMHO it (still) lacks an essential function in the "Verify Digital Signature" part: an automatic refresh/rotation interval to periodically fetch and update the JWKS from a specified URL. Currently, it only supports the upload of a file containing the key. Not enough for a mature solution, which supports enterprise deployments (OIDC integrations with such as Entra ID, Okta, etc.)
Note: I do know that some experts here builded some automation to work around this lacking feature. Great stuff.
Anyway, as I though the effort for the F5 devs should not be huge (they have already some code doing that in their APM OIDC auto-discovery function), I've opened a support case/RFE and got one back =>
RFE ID2294753: AWAF Access profile Verify Digital Signature to support dynamic JWKS retrieval via a configurable URL endpoint
Don't hesitate to open a support case to get it bound to that RFE, the more we are the higher priority will be assigned to implement it (hopefully). đŸ˜€
Alexandre
3 Replies
- Melissa_C
Moderator
Hi,
Could you please let us know where the Access Profile is located in AWAF?
We would like to test this feature, but we have not been able to find it, and there doesn't seem to be any documentation describing where it is configured.
If there is any related documentation or guidance available, we would appreciate it if you could share it with us.
Thank you.
- amolari
Cirrostratus
Hi,
indeed the documentation is not found easily. I guess here:
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com