Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Client Auth via PKI

From Tech-Wiki


F5 BIG-IP client-certificate/iRule reference retained for existing designs.

ⓘ
Validation status
Reviewed against current BIG-IP client-certificate authentication documentation on 27 September 2026.
!
Validate the certificate before trusting certificate fields
Do not treat subject/issuer strings alone as proof of trust. Configure the Client SSL/APM trust and revocation controls required by the application.

Original technical reference

  1. add datagroup CertificateCA
#   String: DigiCert Server CA
#   Value: www.domain.com
when CLIENTSSL_CLIENTCERT {
   set SubCN [findstr [X509::subject [SSL::cert 0]] "CN=" 3 ","]
   set IssCN [findstr [X509::issuer [SSL::cert 0]] "CN=" 3 ","]
   if {[class match $IssCN equals CertificateCA]}{
       set name [class match -value $IssCN equals CertificateCA]
            if {$name ne ""} {
                 if { $name eq $SubCN } {
                     } else {
                       reject
                  }
              } else {
                 reject
             }
             } else {
   }
}

Official and supporting references