Forum Discussion
Arthur_7109
Nimbostratus
Jul 05, 2010What is in [AUTH::response_data] with auth_ssl_cc_ldap authentication
Hi,
I have auth_ssl_cc_ldap working. It checks for the existence in the LDAP server of the user based on the CN in the client certificate.
Now I need an irule that checks that a fi...
Arthur_7109
Nimbostratus
Jul 16, 2010Hi guys,
Here's an update. I had opened case C711900 "auth_ssl_cc_ldap authentication with another (not CN) certificate subject field" and the engineer has "raised an escalation to get this case linked to the CR to add more weight to the priority, so when PD review the RFE list this feature will stand out as having a higher priority.
If you would like to push for this feature more you can also escalate this via the sales channel. Sales have a process by which they can impact the priority of a CR if the issue has a significant impact to you future deployment plans, or if they would benefit (from a sales perspective) in having this feature included in the next release of BIG-IP software.
Please keep an eye out for CR108187 to see if it is included in the next release of BIG-IP software."
So I'll ask our sales guys to push this CR a bit.
Also I checked the APM (though I'd expect this functionality to be also in the LTM *Advanced* client authentication module), but what we need isn't there either. As I understand the "Session variables reference" in the "Configuration Guide for BIG-IP Access Policy Manager" - we can reference session.ssl.cert.l, session.ssl.cert.ou, etc but still no *custom* field in the subject DN. Or is there a way for me to get the DN and parse it myself in an irule?
Arthur
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
