Forum Discussion
jondyke_46152
Nimbostratus
Jan 24, 2011pass through client certificate irule
I am currenlty using the irule below for performing SSL passthrough on traffic. Is there any way I could midify this irule so that it only passed through SSL traffic that has a client certificate at...
jondyke_46152
Nimbostratus
Jan 24, 2011Hi Chris - thanks for the reply.
The rule I have listed is the current rule we use - however this just passes through all SSL traffic (providing pool memeber are availabe) which is a bit blunt. The reason we do passthrough in the first place is that we have two forms of authentication for our site - one certificate based and one using logon and password (database rather than LDAP). If we just do offload the client certificates for the certificate logon never get to the IIS servers so this is why we set it up to do passthough.
What I am after is some pointers on how to change this rule so that it only does passthrough if a client certificate is attached (and pool members are available). Otherwise it just perform SSL offload using the client SSL profile. This way it means we are at least doing some offloading on this site for non-cert users.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects