Forum Discussion
Client cert auth, more than advertised CA filtering?
Quick answer is no, but also that's it's not something that the F5 can control anyway. A server can hint to the client on which certs it can select from, which is what the Advertised list does, but ultimately it's up to the client to perform said filter, and per the RFC it's only based on issuer information.
Might I inquire, the CA that issues two of the certs on the smart card, are they both identity certs (keyUsage contains "Client Authentication"), or is one of these an (email) encryption certificate?
They are both "identity certs", the old cert has a Key usage of Digital Signature, Non-Repudiation and no Enhanced Key usage.
The new cert that has been mandated for authentication is Digital Signature with Enhanced Key usage of Smart Card Login, Client Authentication.
There has been a mandate for web application owners to only be able to authenticate using this new certificate by early next year, and in some of the documentation it can be construed that you cannot allow the other certificates that have been issued by the same CAs.
And of course with the contact info that they give you, no one responds.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com