Forum Discussion
Do you necessarily need an iRule for this? What about configuring client certificate authentication in the client SSL profile? Check whether this will meet your requirements.
K12140946: Configuring the BIG-IP system to perform two-way SSL authentication
The BIG-IP system supports TLS 1.3 Client Certificate Authentication in 14.1.0.1 and later.
https://my.f5.com/manage/s/article/K10251520
- ronsenguptaApr 22, 2023Nimbostratus
Thanks for the response, this needs to be without the F5 doing TLS termination. The 2 way auth need to be directly between the client and server where F5 LTM will act as TCP pass through, however should be able to check that client using a cert without TLS termination.I was thinking about checking the TLS handshake, as TLS handshake happens before the encrypted message exchange, however TLS handshake does not have client cert it only has cipher suites information.
- Apr 23, 2023
I don't think you will be able to get the F5 to check the client certificate without applying a client SSL profile (with client authentication enabled) to the virtual server.
The solution proposed by AlexBCT would work if you were able to terminate SSL on the F5 (as I believe the CLIENTSSL_CLIENTCERT iRule event requires a client SSL profile)