Forum Discussion

Bastiaan_Bakker's avatar
Bastiaan_Bakker
Icon for Nimbostratus rankNimbostratus
Apr 20, 2006

support for 'SSL::payload'

Hi,

 

 

I'm trying to create an iRule for injecting client certificate information in a Big-IP SSL terminated POP3 service, so the backend POP3 servers can identify clients based on their SSL certificate.

 

However TCP::payload returns/manipulates the encrypted SSL traffic, rather than the decrypted data.

 

On this forum I read there are/were plans for adding SSL::payload, SSL::collect, etc. This sounds exactly what I need.

 

Can any of the developers comment on whether this feature will be added indeed, and roughly when to expect it?

 

 

Thanks in advance,

 

 

Bastiaan Bakker

 

Senior Software Engineer

 

E.Novation LifeLine Networks bv

 

 

  • bl0ndie_127134's avatar
    bl0ndie_127134
    Historic F5 Account
    If you are using 9.2 or later release try experimenting with the stream profile. Here is some data on how it works Click here

     

     

  • Thanks for the hint. This streaming profile feature looks like a much more elegant approach than 'SSL::payload replace'. Now, let's see if I can get this to work!

     

     

    Best Regards,

     

     

    Bastiaan