Forum Discussion
Jason_Witt_4207
Oct 24, 2005Historic F5 Account
iRule to require SSL Client Certs for a URI
Working on developing a Rule based on the SSL Client Cert for URI in Docs and Tips. We first tried the rule verbatim with the exception of changing the URI to match what they wanted to protect. This...
James_Yang_9981
Altostratus
May 28, 2006I have tested this rule. it seems that start with profile cert ignore, then changing the cert mode to require, client will prompt for a certificate. but after apply the certificate. the connection will be rejected.
after do a tcpdump of the ssl connection. it seems that client will setup a new TCP connection to VS after renegotiation, that cause the rules can't process in same session. so the connection breaks.
how can we keep SSL::renegotiation in same connection?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
