Forum Discussion
irule for cn value client certificate authentication
Hi, We are doing client certificate authentication using client ssl profile with request setting and it is working. We want to achieve following (requirement is little weired) -
- Anyone coming without client certificate, should be able to connect
- Any client who presents its certificate to server should be able to connect only if it has specific CN.
The point2 would require the irule otherwise clients with any CN would be able to connect.
Thanks
1 Reply
- ekaleido
Cirrus
What's the point? If they present a bad certificate they could just stop sending a certificate and be able to get in. And checking the CN is not a very secure thing to check since it could be a faked value. You could potentially give a malicious person access to something you're trying to protect.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com