Forum Discussion
Antoine_80417
Nimbostratus
Apr 13, 2011Multiple certificate authorities and authentication profiles
Hello,
This is my first post on this forum so first, let me introduce myself : I'm a network an security engineer, I work for a company that uses quite a lot of F5 appliances as GTMs, LCs or...
Joel_Moses
Nimbostratus
Apr 15, 2011Hoolio, maybe you know this one since I know you've done work with extended cert revocation checking in the past: is it possible to read the issuer from a presented client cert and then use that value to change what OCSP profile you use in AUTH::start? Normally it's invoked with "[AUTH::start pam default_ssl_ocsp]", but if you know the specific name of the profile (say, my_ocsp_profile), can it be invoked with either "[AUTH::start pam tmm_my_ocsp_profile]" or "[AUTH::start pam my_ocsp_profile]"? The Wiki is a little weak in this area.
The reason I ask is that I think that's what Antoine is asking for: the ability to detect which issuer the presented client cert has, and switch between a few different revocation profiles (OCSP or CRLDP) based on that value. Might be able to be done in a modification to the authentication iRule if AUTH::start can be switched in that way.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
