Forum Discussion
Certificate Logging via iRule
Certificate Logging via iRule -
I think I'm missing something pretty simple. My goal is to log the CN, Subject, Serial# of all Client's hitting my VIP. Is there a way to accomplish this without turning on "Require" Mode under Client Authentication via the SSL Profile. I can't seem to find a Wiki Article around this.
Thanks,
- Hamish
Cirrocumulus
Sorry, your question feels a bit ambiguous.
Do you wish to log the SERVER side certificate information? or the CLIENT side certificate information?
If you wish to log the CLIENT side, then you'll have to REQUIRE a client cert. Because otherwise you have no guarantee that there will be one to log.
Yes, I was trying to request the certificate details via CLIENT side. I wasn't sure if the only way to snatch this data up was to "REQUIRE" or "REQUEST" it via the SSL Profile option. I had thought there would be a way to grab this data in another method without having to allow it.
Is there a way to grab the Server Side Certificate via iRule without the SSL Profile option selected?
Thanks,
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com