Forum Discussion
Yes, well. its step up auth. so its not done on the access policy. but on a pre request policy. and also has to be done as a subroutine, so my reading tells me that per request subroutines don't have access to the session variables as writeable. only readable.
quick check via the gui interface and it show that the cert info is in the per request sub session variables. how can I insert headers from a subroutine in a pre request policy .. i thinking the only way is to use a irule event ...
but this seems rather hard.
Note - i am note sure when access_acl_allowed is fired, but I have checked the session variables - no sign of the cert in the main session variables :(
Hi
Not so sure about that. but happy to proven wrong.
of if follow the flow i had above the person enters on a different uri that doesn't need cert or step up
the AP landing uri is the one set at the creating of the AP, not on subsequence request ?
also the AP associated with this is not for www.example.com but on auth.example.com.
so I would need to build a branch for every vs i had - that would be comber some