awaf
15 TopicsAWAF Access Profile, missing a configurable JWKS URL - RFE
The AWAF Access Profile functionality (introduced in 17.5) is potentially a great feature, but IMHO it (still) lacks an essential function in the "Verify Digital Signature" part: an automatic refresh/rotation interval to periodically fetch and update the JWKS from a specified URL. Currently, it only supports the upload of a file containing the key. Not enough for a mature solution, which supports enterprise deployments (OIDC integrations with such as Entra ID, Okta, etc.) Note: I do know that some experts here builded some automation to work around this lacking feature. Great stuff. Anyway, as I though the effort for the F5 devs should not be huge (they have already some code doing that in their APM OIDC auto-discovery function), I've opened a support case/RFE and got one back => RFE ID2294753: AWAF Access profile Verify Digital Signature to support dynamic JWKS retrieval via a configurable URL endpoint Don't hesitate to open a support case to get it bound to that RFE, the more we are the higher priority will be assigned to implement it (hopefully). 😀 Alexandre132Views1like3CommentsF5 BOT DEFENSE AWAF blocked some legitimate browsers
Hi Community, May I ask if F5's AWAF Bot Defense is still not being refined cause it causes some request from browsers to log it as a Malicious Bot, and therefore, this causes to block the request? May I ask what is the best practice for implementing the BOT defense feature? Thank you and have a nice day! Regards, ZeigfredSolved501Views1like2Comments