Forum Discussion
Andy_4962
Nimbostratus
Feb 02, 2010Client Certificate Request on demand
Hello group!
I can not seem to get a client cert request to appear to the end user a second time in a single session.
For authentication purposes, I want to allow the end...
Andy_4962
Nimbostratus
Feb 03, 2010Aaron,
Your on the right track now, sorry it was hard to explain.
I logged the SSL::sessionid and with or without SSL::session invalidate the session ID is changed, but no, still no additional prompt from IE7. I suspected the browser was causing that, but I can't find a setting to force it to prompt at each new SSL negotiation.
I have performed TCP dumps as suggested, and it looks like the BigIP is acting as it should. I can see the re-negotiation occuring and the client being prompted for a cert, and it looks like the client is returning the same response. I am moving on to test with different browsers to try to verify that this is a client side issue. Since I have little to no control of the end users browser, if I can't find a way to trick the browser into restarting it's session, I may be stuck. I'll post more info after testing.
Thanks!
Andy
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects