Forum Discussion
smilanko_261688
Cirrus
Jun 14, 2016Prompt for certificates APM
My scenario:
I am attempting to prompt the user for the certificates he wishes to use to authenticate them self to my application. From the certificate, all that I care about is the username tha...
wonsoo_41223
Jun 15, 2016Historic F5 Account
I think it should be better to post on APM instead of iRule part.
1. The CA certificate (tomcat-cert) move from CA certificate in SSL forward proxy to "Trusted Certificate Authorities" in Client Authentication part.
2. My understanding is that "On-Demand Cert Auth" can trigger to request client side to present client certificate with initiating a new SSL session. It doesn't matter to set "ignore" in Client Certificate field. The best way to troubleshooting for this case is to capture tcpdump for checking SSL handshake. Some of case, browser silently provide client certificate without prompt.
* https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-authentication-single-sign-on-11-5-0/16.html
3. For UPN value extraction, check this url :
* https://support.f5.com/kb/en-us/solutions/public/17000/000/sol17063.html
4. If APM policy is changed, please update policy with clicking "Apply Access Policy". Otherwise old policy will be running in the APM access profile.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects