Forum Discussion
iRule for client certificate
We would like to have F5 configured to not always request client certificate authentication, but to request it only when the path matches specific URL
- Simon_Blakely
Employee
Look at SSL Renegotiation:
WhiteBoard Wednesday: SSL Renegotiation
SSL Profiles Part 6: SSL Renegotiation
- Simon_Blakely
Employee
- Bill_at_F5
Employee
This is a good use case for APM's "Per Request Policy" feature. You can create URL branches which require authentication and portions of the site which does not. This could also enable "step-up" authentication use cases where access to certain parts of a site could require stronger authentication.
On-Demand Cert Authentication or ODCA is an option in a Per Request Policy.
On Demand Certificate Authentication
How Step-up Authentication works:
Step-up Authentication with Client Certificate example:
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com