Forum Discussion
psor_73734
Nimbostratus
Aug 18, 2009client certificate authentication for a particular directory
Hi
I need to use client certificate authentication for a particular directory, for example:
on
https://demo.com (no authentication needed)
https://demo.com/auth (we requiere to ask for client certificate with oscp verification)
I could configure it for entire URL but not for particular directory.
Is there any way to do that?
Thanks you
6 Replies
- hoolio
Cirrostratus
Hi, - psor_73734
Nimbostratus
Aaron, - hoolio
Cirrostratus
It would be good to upgrade to the latest 9.4.x version, 9.4.7 as there have been a number of important fixes since 9.4.4. For OCSP validation of the client cert, there is a default OCSP verification iRule provided. You can reference that for ideas to start with. Once I have a working version I can post that as well. - psor_73734
Nimbostratus
I understand what you mean, but If I use request mode, clients will always be prompted to present a client certificate for entire site.. that's not what I want. - hoolio
Cirrostratus
You'll need to set the client SSL profile to ignore client certs. In the iRule, after examining the requested URI and finding a request to a restricted URI, you'll want to renegotiate the SSL handshake with the client and dynamically set the client SSL filter to request a client cert. You can do this using: - psor_73734
Nimbostratus
I will try it.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects