Forum Discussion
sfntauth_180479
Nimbostratus
Dec 17, 2014Certificate based user authentication to F5 APM
We are in need to test CBA authentication to F5 using PKI tokens.
Instead of proving AD username and password, user inserts his token(Having user certificate) to client machine and provides pin to th...
amolari
Cirrostratus
Dec 18, 2014F5 will be able to check the user certificate but in no way if it's on a token or not (this "info" is not available at all in the communication). Here it's a PKI policy that helps. You should either have
- certificates on token are issued by a specific CA (higher assurance): the APM will check only client certs issued by that CA
- certificates on token have specific properties: the APM can check this properties (that will require an iRule)
Hopefully you have already deployed you certificates in a way that you can apply either 1) or 2)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects