Forum Discussion
JCMATTOS_41723
Nimbostratus
Jul 22, 2010Client Certificate Authentication w/ specific url's?
We have an LTM 8400 9.4.7 and have a new requirement to use client certificate authentication for a certain url web service. We have a very specific need to protect the following web service https://www.xyz123.com/Service/Service.asmx using this method. However, only this specific web service needs to be authenticated in this fashion, all other services should be accessible with normal server certificate authentication. I see many examples of how to enable it per virtual server site, but none for specific url web services. Any help is appreciated. Thx!
- hoolio
Cirrostratus
Hi JC, - JCMATTOS_41723
Nimbostratus
Thx Hoolio! We are not planning on upgrading to 10.1/10.2 until next year sometime. After reviewing some of your recommended options, it seems that we would rather avoid any vulnerabilities if possible and go with trying the subdomain approach first. The OCSP article looked interesting but required a 9.4.8 HF3 upgrade which we are not ready to do just yet. We certainly don't mind being a case study, in hopes we can collectively find a good solution in the end. Do you have an example of the subdomain method you mentioned earlier? This sounds like it might work well, the part I'm a little confused is if we create a new subdomain VS for all Client Certificate Authentication do we only redirect the specific URI's from the main VS to this one? In other words, if our client hits https://www.abc123...rvice.asmx on the main VS and gets redirected to https://www.abc321...rvice.asmx on the new subdomain VS using CCA (2-way ssl) and works as expected. However, if the same client hits https://www.abc123.com/ClaimService on the main VS would he get redirected as well? And at that point can he just use normal SSL certificate authentication to connect to this service?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects