Forum Discussion
gowenfawr
Nimbostratus
Aug 20, 2013How to mask HTTP Authorization header in ASM logs, similar to sensitive parameters?
The subject pretty much says it all. We use the "Sensitive Parameters" setting described in Chapter 9 of the "Configuration Guide for BIG-IP Application Security Manager" to ensure that passwords an...
Torti
Cirrus
Aug 21, 2013... and you should trust your admins ;-) they always have the possibility to see sensitive data. It is only a nice feature, if you save the log files on an external server, you send a report to another employee or people have access to the system, who shouldn't see the sensitive data.
gowenfawr
Nimbostratus
Aug 21, 2013I understand and agree - an admin who could see this, could also run tcpdump/ssldump from the F5 and grab the same data. The difference is that I do have to show auditors things like the log interface, and I don't have to explain ssldump to them.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects