Forum Discussion
Antoine_80417
Nimbostratus
Apr 13, 2011Multiple certificate authorities and authentication profiles
Hello,
This is my first post on this forum so first, let me introduce myself : I'm a network an security engineer, I work for a company that uses quite a lot of F5 appliances as GTMs, LCs or...
Michael_Yates
Nimbostratus
Apr 15, 2011I believe that the CRL in the Client Authentication portion of the SSL Profile (Client) is a list of revoked Client Certificates. It should not contain CA's.
If you want to filter SSL Traffic for the client and only accept SSL Certificates issued by certain CA's then you are probably going to have to write an iRule to do that.
In the CLIENTSSL_CLIENTCERT Event you can use the X509 Command:
Overall Command:
http://devcentral.f5.com/wiki/default.aspx/iRules.X509
Retrieve Issuer:
http://devcentral.f5.com/wiki/default.aspx/iRules/X509__issuer.html
Hope this helps.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
