Forum Discussion
On-Demand Cert Auth Fallback
It's the difference between a fail open connection and fail closed connection. The Require option provides a fail closed connection. If for any reason the client cannot satisfy the certificate request, or the client's certificate cannot be validated or trusted, the connection is closed. The Request option, however, allows the connection to proceed. This option also allows you to apply additional logic after the SSL handshake, as in to perform an HTTP redirect on validation/trust failure.
The "is it secure" question is relative to what you're doing in the fallback branch. The SSL handshake will complete regardless, so you must do something in that fallback branch that prohibits further access.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com