Forum Discussion
Client cert auth, more than advertised CA filtering?
you Should request the IETF to add such filter in tls specifications...
in tls 1.2, section 7.4.4, the certificate request message structure is the following
struct {
ClientCertificateType certificate_types<1..2^8-1>;
SignatureAndHashAlgorithm
supported_signature_algorithms<2^16-1>;
DistinguishedName certificate_authorities<0..2^16-1>;
} CertificateRequest;
F5 can’t send client more information than described in this message
- action_-Jun 14, 2019
Altostratus
Thank you for your answer and the reference.
I'll have to report back up the chain that we can't restrict what the server requests for client cert any more granularly than the advertised CA.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com