Forum Discussion
Tom_Lebel_53961
Nimbostratus
Jul 07, 2006need a rule to force client certs
I am in an odd dilema. I need to write an iRule to do the same thing as 'require' setting does for client certs.
Problem exists, because I need to require client certs by regulation, and one of th...
Tom_Lebel_53961
Nimbostratus
Jul 10, 2006Thanks, that did get me started. Now I have this:
when HTTP_REQUEST {
if {[HTTP::uri] starts_with "/ASITE/" }
{HTTP::collect [HTTP::header Content-Length]
SSL::cert mode require
SSL::renegotiate}
else
{SSL::cert mode request
}
}but it doesn't work.
Originally I had an HTTP::release after the SSL::cert mode request in the else statement, but I don't know what that's supposed to do.
On the server side, I've got the Apache set up, that when a call to /ASITE/ comes in, it redirects to the real site URI, so I figured, at that point it would only request the client cert, and not require it.
Thoughts?
Tom
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects