Forum Discussion
NGINX vs. iRule - Client certificate validation based on URI and other things
Hey Andreia - were you able to figure it out? I've sent this thread to a colleague to see if they can offer some help.
- AndreiaFeb 28, 2023
Cirrus
Ih, Leslie_Hubertus.
I have read every possible article on the subject, but I have not been able to solve it.
I quote the NGINX code because there it is very simple to do "If URI /auth, then validates the client's certificate, any other URI does not."
In BIG-IP it is being a bad experience. Enriching, but bad.
The iRule works, but I have a problem with the list of client certificates. Because I need to validate ANY client certificate data. And not just DNs, or Issuers, or serial, etc. that I can put in a list or datagroup.
I need to read the "Trusted Certificate Authorities" in the SSL Client Profile, but through an IRule. It is possible?Thank you!
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
