Client Auth via PKI
From Tech-Wiki
More actions
F5 BIG-IP client-certificate/iRule reference retained for existing designs.
Validation status
Reviewed against current BIG-IP client-certificate authentication documentation on 27 September 2026.
Validate the certificate before trusting certificate fields
Do not treat subject/issuer strings alone as proof of trust. Configure the Client SSL/APM trust and revocation controls required by the application.
Original technical reference
- add datagroup CertificateCA
# String: DigiCert Server CA
# Value: www.domain.com
when CLIENTSSL_CLIENTCERT {
set SubCN [findstr [X509::subject [SSL::cert 0]] "CN=" 3 ","]
set IssCN [findstr [X509::issuer [SSL::cert 0]] "CN=" 3 ","]
if {[class match $IssCN equals CertificateCA]}{
set name [class match -value $IssCN equals CertificateCA]
if {$name ne ""} {
if { $name eq $SubCN } {
} else {
reject
}
} else {
reject
}
} else {
}
}