Configure SSL-based header insertion
-
Insert the entire client certificate, if necessary, a hash (also known as a fingerprint or thumbprint) of the entire client certificate.
-
Insert only the specific fields from the certificate, such as the subject, serial number, issuer, signature, SSL session ID, cipher suite.
-
Insert the not-before or not-after date used to determine certificate validity.
ctrlpol) is created to perform client authentication if a request is received for the URL /testsite/file5.html. A data policy (datapol) is created to perform an action (act1) if client authentication is successful. An SSL action (act1) is added to insert the certificate details and issuer's name in the request before forwarding the request. For other URLs, client authentication is disabled. The policies are then bound to an SSL virtual server (ssl_vserver) that receives the SSL traffic.
Command-line example of configuring SSL-based header insertion
add ssl action act1 -clientCert ENABLED -certHeader mycert -clientcertissuer ENABLED -certIssuerHeader myissuer
add ssl policy datapol -rule HTTP.REQ.URL.EQ("/testsite/file5.html") -action act1
add ssl policy ctrlpol -rule HTTP.REQ.URL.EQ("/testsite/file5.html") -action CLIENTAUTH
bind ssl vserver ssl_vserver -policyName ctrlpol -priority 1
bind ssl vserver ssl_vserver -policyName datapol -priority 1
Done
Configure SSL-based header insertion by using the GUI
-
Navigate to Traffic Management > SSL > Policies.
-
In the details pane, on the Actions tab, click Add.
-
In the Create SSL Action dialog box, set the following parameters:
-
Name*
-
Client Certificate
-
Certificate Tag
-
Client Certificate Issuer
-
Issuer Tag
* A required parameter -
-
Click Create, and then click Close.
-
On the tab, click Add to create a control policy.
-
In the Create SSL Policy dialog box, set the following parameters:
-
Name*
-
Expression
-
Request Action
* A required parameter -
-
Click Create, and then click Close.
-
Create a data policy by repeating steps 5 through 7.
-
In the navigation pane, expand SSL Offload, and then click Virtual Servers.
-
In the details pane, from the list of virtual servers, select the virtual server to which you want to bind the SSL policies, and then click Open.
-
In the Configure Virtual Server (SSL Offload) dialog box, click SSL Settings, and then click SSL Policies.
-
In the Bind/Unbind SSL Policies dialog box, click Insert Policy. Under Policy Name, select the policy that you created in steps 5 through 7.
-
Click OK, and then click Close. A message appears in the status bar, stating that the policy has been bound successfully.
-
Repeat steps 12 and 13 and select the policy that you created in step 8.
Configure an SSL policy action for inserting client certificate thumbprint in the HTTP header
Configure an SSL action for inserting client certificate thumbprint by using the CLI
add ssl action <name> -clientCertFingerprint ( ENABLED | DISABLED ) -certFingerprintHeader <string> -certFingerprintDigest <certFingerprintDigest>
add ssl action act1 -clientcertfingerprint ENABLED -certfingerprintdigest SHA1 -certfingerprintheader example
Donesh ssl action act1
1) Name: act1
Type: Data Insertion
Cert Fingerprint Header: ENABLED
Cert-Fingerprint Tag: example
Cert-Fingerprint Digest Algorithm: SHA1
Hits: 0
Undef Hits: 0
Action Reference Count: 0
Doneadd ssl policy pol1 -rule true -action act1
Donebind ssl vserver v1 -policyName pol1 -priority 10
Donesh ssl vserver v1
Advanced SSL configuration for VServer v1:
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED Ephemeral RSA: ENABLED Refresh Count: 0
Session Reuse: ENABLED Timeout: 120 seconds
Cipher Redirect: DISABLED
SSLv2 Redirect: DISABLED
ClearText Port: 0
Client Auth: ENABLED Client Cert Required: Mandatory
SSL Redirect: DISABLED
Non FIPS Ciphers: DISABLED
SNI: DISABLED
OCSP Stapling: DISABLED
SSLv2: DISABLED SSLv3: DISABLED TLSv1.0: DISABLED TLSv1.1: ENABLED TLSv1.2: DISABLED
Push Encryption Trigger: Always
Send Close-Notify: YES
ECC Curve: P_256, P_384, P_224, P_521
1) CertKey Name: intca6 CA Certificate CRLCheck: Mandatory CA_Name Sent
2) CertKey Name: intca5 CA Certificate CRLCheck: Mandatory CA_Name Sent
3) CertKey Name: intca4 CA Certificate CRLCheck: Mandatory CA_Name Sent
4) CertKey Name: intca3 CA Certificate CRLCheck: Mandatory CA_Name Sent
5) CertKey Name: intca2 CA Certificate CRLCheck: Mandatory CA_Name Sent
6) CertKey Name: intca1 CA Certificate CRLCheck: Mandatory CA_Name Sent
Data policy
1) Policy Name: pol1 Priority: 10
1) Cipher Name: DEFAULT
Description: Default cipher list with encryption strength >= 128bit
Done
Configure an SSL action for inserting client certificate thumbprint by using the GUI
-
Navigate to Traffic Management> SSL> Policies.
-
In the details pane, select the SSL Actions tab, and click Add.
-
In the Create SSL Action dialog box, set the following parameters:
-
Name*
-
Client Certificate Finger Print
-
FingerPrint Tag
-
FingerPrint Digest *A required parameter
-
-
Click Create.
-
Select the SSL Policies tab, and click Add.
-
In the Create SSL Policy dialog box, set the following parameters:
-
Name*
-
Action
-
Expression *A required parameter
-
-
Click Create.
-
Navigate to Traffic Management> Load Balancing > Virtual Servers.
-
In the details pane, from the list of SSL virtual servers, select the virtual server to which you want to bind the SSL policy, and then click Edit.
-
In Advanced Settings, click SSL Policies.
-
Click below SSL Policy, and in Policy Binding dialog box, select the policy created earlier and assign a priority.
-
Click Bind.