Forum Discussion
ekaleido
Cirrus
Aug 19, 2016What is this iRule doing?
I am apparently losing my mind. So without giving my understanding for the following iRule, can someone wiser than I explain what this iRule is doing?
when CLIENTSSL_HANDSHAKE {
if {[SSL::cert cou...
Kevin_Stewart
Employee
Aug 19, 2016During the CLIENTSSL_HANDSHAKE event, the client is presenting a certificate to me? And that is where I am getting $cert_hash which I ultimately compare to $Expected_hash?
Yes. This iRule assumes that you're doing "mutual" SSL, which is defined in the Client Authentication section of the clientssl profile (request or require).
The data group contains CN and hash values for "known" client certificates, which would have been entered through some previous registration process.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
