Forum Discussion
Is it possible to discard client certificate session information after iRule processing?
We are implementing a service that has a MASSL requirement, and we have an iRule that looks at the DN and CN values of the client cert. In testing we have seen SSL consuming a large enough proportion of memory that the connection reaping is activated. If we weren't using an iRule we could disable the 'retain certificate' feature as described here: K19802202: Disabling the Retain Certificate option in an SSL profile to reduce memory pressure.
Is there a way to retain the certificate in session variables, complete iRule processing and then clear or discard the session variables?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
