Forum Discussion
Client Certificate Authentication - Machine or Client cert APM method
- May 05, 2016
Hello,
Machine cert auth is heavy for the endpoint. The browser need admin rights to access and present the certificate located within the local machine store. That's why you need to install an helper from F5 on client devices. I think that it works with Microsoft devices only. My rules are if you need a 802.1x like solution so machine cert validation is the right solution. Otherwise, I would recommend to go with client cert auth that offer more flexibility and can be used outside APM. In both case Crl and ocsp checking works the same.
Hello,
Machine cert auth is heavy for the endpoint. The browser need admin rights to access and present the certificate located within the local machine store. That's why you need to install an helper from F5 on client devices. I think that it works with Microsoft devices only. My rules are if you need a 802.1x like solution so machine cert validation is the right solution. Otherwise, I would recommend to go with client cert auth that offer more flexibility and can be used outside APM. In both case Crl and ocsp checking works the same.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com