Forum Discussion
Ron_Kim_110696
Jan 11, 2007Nimbostratus
iRule example to extract specific X509 information: SOL5171
I can't get this iRule to work.
The variable $sn in the HTTP_REQUEST section does not have a value.
It is working in the CLIENTSSL_CLIENTCERT section.
Variables do not seem t...
Ron_Kim_110696
Feb 21, 2007Nimbostratus
Thanks.
We now have an iRule that works.
Now how do we use the "SSL:cert mode request" command to toggle ON and OFF depending on the URI?
And how do we handle the case when the client does not have an Client SSL cert.
What would be the best way to achieve the following?
* Create a Class that has a list of URI's.
* If the URI is listed in the Class, then do not Request the Client SSL cert.
* If the URI is NOT in the Class, then ask for the Client SSL cert.
- Client does NOT have or does NOT have the proper Client SSL cert, then sent them to an error page. (I guess a good filter for the Proper SSL cert would be based on the Issuer.)
- The Client DOES have a valid SSL cert, then insert information into an HTTP header.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects