Forum Discussion
mishpan_70054
Nimbostratus
Dec 03, 2012logging Subject Server Certificate -in case Server side profile
Hi All
I have virtual configure with clientssl & serverssl profile enable. I like to know how I can log the subject details of the server certificate use by real server when lb communicat...
nitass
Employee
Dec 03, 2012SSL::cert is not valid on server-side.
SSL::cert
Returns the X509 SSL certificate at the specified index in the peer certificate chain, where index is a value greater than or equal to zero. A value of zero denotes the first certificate in the chain, a value of one denotes the next, and so on. This command is currently applicable only under a client-side context and returns an error within a server-side context.
SSL::cert
https://devcentral.f5.com/wiki/iRules.SSL__cert.ashx
so, i understand you have to collect tcp payload and parse certificate subnet by yourself. it could be something similar to what Colin and Joel have done in article below.
Multiple Certs, One VIP: TLS Server Name Indication via iRules by Colin
https://devcentral.f5.com/tutorials/tech-tips/multiple-certs-one-vip-tls-server-name-indication-via-irules
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
