Forum Discussion
Arthur_7109
Nimbostratus
Jul 05, 2010What is in [AUTH::response_data] with auth_ssl_cc_ldap authentication
Hi,
I have auth_ssl_cc_ldap working. It checks for the existence in the LDAP server of the user based on the CN in the client certificate.
Now I need an irule that checks that a fi...
hoolio
Cirrostratus
Jul 06, 2010Hi Arthur,
I would have expected AUTH::response_data to return the auth status in 'ccldap:reply:status ' for successful auth attempts. If you're not seeing anything on successful attempts, I'd open a case with F5 Support.
I don't expect you'll be able to get any other detail about the user from LDAP though. The cert validation seems to be hardcoded to check one field when supplied with the full cert. And the auth response only contains details about the auth status--not arbitrary ldap query results.
It's a shame that you can't do a more arbitrary auth database query (or even queries) and check for more than a binary response. A lot of customers have mentioned similar requests.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
