Forum Discussion
Maxim_Taskov_90
Nimbostratus
Nov 15, 2011Client Certificate Validation by Subject
I am trying to use the common name CN from the x509::subject variable to validate a client certificate. I used the rule from teh following post as a sample:
http://devcentral.f5.com/Communit...
Maxim_Taskov_90
Nimbostratus
Nov 17, 2011Thanks hoolio, I will open a case with F5 but have little faith as they usually send me right back to DevCentral if it is not a hardware issue. I will let you know the outcome.
Nitass, I am not sure how to create the certificate with blank subject field in openssl. I actually stumbled on this issue by accident as I never thought you could have a certificate with blank subject field but I guess you can. In my initial testing of my iRule I just grabbed the first certificate I had in my machine certificate store with the Client Authentication role and it happened to be one issued via auto-enrollment by Microsoft Certificate Authority for the purpose of machine level authentication for a different process. I wouldn't have pursued the anomaly if the connection was rejected but I guess iRule validation fails on TCL error. This appears to be a dangerous exploit and that is why I wanted to find the reason for it and a solution to the obvious security problem.
I can send you the certificate, key and trusted root chain in a separate email if you provide your contact details. Please disable CRL checking in your test configuratuion as I will revoke this certificate for understandable reasons.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects