SSL built-in actions and user-defined actions
-
DOCLIENTAUTH—Perform client certificate authentication. (Not supported for TLS1.3)
-
NOCLIENTAUTH—Do not perform client certificate authentication. (Not supported for TLS1.3)
-
RESET—Close the connection by sending an RST packet to the client.
-
DROP—Drop all packets from the client. The connection remains open until the client closes it.
-
NOOP—Forward the packet without performing any operation on it.
Examples of built-in actions in a policy
add ssl policy pol1 -rule CLIENT.SSL.CIPHER_EXPORTABLE.NOT -reqAction DOCLIENTAUTH
add ssl policy pol1 -rule CLIENT.SSL.CLIENT_CERT.VERSION.EQ(2) -reqAction NOOP
add ssl policy pol1 -rule CLIENT.SSL.CLIENT_CERT.VERSION.EQ(2) -reqAction DROP
add ssl policy pol1 -rule CLIENT.SSL.CLIENT_CERT.VERSION.EQ(2) -reqAction RESET
Client certificate verification with policy based client authentication
Set client certificate verification to optional using the CLI
add ssl action <name> ((-clientAuth ( DOCLIENTAUTH | NOCLIENTAUTH ) [-clientCertVerification ( Mandatory | Optional )]
add ssl action sslact -clientauth DOCLIENTAUTH -clientcertverification OPTIONAL
Set client certificate verification to optional using the GUI
-
Navigate to Traffic Management > SSL > Policies.
-
On the SSL Actions tab, click Add.
-
Specify a name and in the Client Certificate Verification list, select Optional.
User-defined SSL actions
Configure a user-defined SSL action by using the CLI
add SSL action <name> -clientAuth(DOCLIENTAUTH | NOCLIENTAUTH) -clientCert (ENABLED | DISABLED) certHeader <string> -clientHeader <string> -clientCertSerialNumber (ENABLED | DISABLED) -certSerialHeader <string> -clientCertSubject (ENABLED | DISABLED) -certSubjectHeader <string> -clientCertHash (ENABLED | DISABLED) -certHashHeader <string> -clientCertIssuer (ENABLED | DISABLED) -certIssuerHeader <string> -sessionID (ENABLED | DISABLED) -sessionIDheader <string> -cipher (ENABLED | DISABLED) -cipherHeader <string> -clientCertNotBefore (ENABLED | DISABLED) -certNotBeforeHeader <string> -clientCertNotAfter (ENABLED | DISABLED) -certNotAfterHeader <string> -OWASupport (ENABLED | DISABLED)show ssl action [<name>]
add ssl action Action-SSL-ClientCert -clientCert ENABLED -certHeader "X-Client-Cert"show ssl action Action-SSL-ClientCert
1) Name: Action-SSL-ClientCert
Data Insertion Action:
Cert Header: ENABLED Cert Tag: X-Client-Cert
Done
Configure a user-defined SSL action by using the GUI
Configure an SSL action to forward client traffic to another virtual server
-
The appliance does not have a certificate.
-
The appliance does not support a specific cipher.
-
CLIENT.SSL.CLIENT_HELLO.CIPHERS.HAS_HEXCODE
-
CLIENT.SSL.CLIENT_HELLO.CLIENT_VERSION
-
CLIENT.SSL.CLIENT_HELLO.IS_RENEGOTIATE
-
CLIENT.SSL.CLIENT_HELLO.IS_REUSE
-
CLIENT.SSL.CLIENT_HELLO.IS_SCSV
-
CLIENT.SSL.CLIENT_HELLO.IS_SESSION_TICKET
-
CLIENT.SSL.CLIENT_HELLO.LENGTH
-
CLIENT.SSL.CLIENT_HELLO.SNI
-
CLIENT.SSL.CLIENT_HELLO.ALPN.HAS_NEXTPROTOCOL (from release 13.0 build 61.x)
forward is added to the add SSL action command and a new bind point CLIENTHELLO_REQ is added to the bind ssl vserver command.
Configuration using the CLI
add ssl action <name> -forward <virtual server name>
add ssl policy <name> -rule <expression> -action <string>
bind ssl vserver <vServerName> -policyName <string> -priority <positive_integer> -type <type>
add ssl action act1 -forward v2
add ssl policy pol1 -rule client.ssl.client_hello.ciphers.has_hexcode(0x002f) -action act1
bind ssl vserver v1 -policyName pol1 -priority 1 -type CLIENTHELLO_REQ
Configuration using the GUI
-
In SSL Actions, click Add.
-
In Create SSL Action, specify a name for the action.
-
In Forward Action Virtual Server, select an existing virtual server or add a new virtual server to forward the traffic to.
-
Optionally, set other parameters.
-
Click Create.
-
In SSL Policies, click Add.
-
In Create SSL Policy, specify a name for the policy.
-
In Action, select the action that you created earlier.
-
In Expression Editor, enter the rule to evaluate.
-
Click Create.
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Add or select a virtual server.
-
In Advanced Settings, click SSL Policies.
-
Click in the SSL Policy section.
-
In Select Policy, select the policy that you created earlier.
-
In Policy Binding, specify a priority for the policy.
-
In Type, select CLIENTHELLO_REQ.
-
Click Bind.
-
Click Done.
SSL action to selectively pick CAs based on SNI for client authentication
-
Add a CA certificate group.
-
Add certificate-key pairs.
-
Bind the certificate-key pairs to this group.
-
Add an SSL action.
-
Add an SSL policy. Specify the action in the policy.
-
Bind the policy to an SSL virtual server. Specify the bind point as CLIENTHELLO_REQ.
Configuration using the CLI
add ssl caCertGroup <caCertGroupName>
add ssl certkey <certkey_name> -cert <cert> -key <key>
bind ssl caCertGroup <caCertGroupName> <certkey_name>
add ssl action <name> -caCertGrpName <string>
add ssl policy <name> -rule <expression> -action <string>
bind ssl vserver <vServerName> -policyName <string> -priority <positive_integer> -type CLIENTHELLO_REQ
add ssl cacertGroup ca_cert_group
add ssl certkey ca_certkey1 -cert cacert1 -key cakey1
add ssl certkey ca_certkey2 -cert cacert2 -key cakey2
add ssl certkey snicert -cert snicert -key snikey
bind ssl cacertGroup ca_cert_group ca_certkey1
bind ssl caCertGroup ca_cert_group ca_certkey2sh ssl caCertGroup ca_cert_group
CA GROUP NAME: ca_cert_group
ACTIONS REFERRING: 1
1) CertKey Name: ca_certkey1 CA Certificate CRLCheck: Optional CA_Name Sent
2) CertKey Name: ca_certkey2 CA Certificate CRLCheck: Optional CA_Name Sentadd ssl action pick_ca_group -cacertGrpName ca_cert_groupsh ssl action pick_ca_group
1) Name: pick_ca_group
Type: Data Insertion
PickCaCertGroup: ca_cert_group
Hits: 0
Undef Hits: 0
Action Reference Count: 1add ssl policy snipolicy -rule client.ssl.client_hello.sni.contains("abc") -action pick_ca_group
bind ssl vserver v_SSL -policyName snipolicy -type CLIENTHELLO_REQ -priority 10sh ssl policy snipolicy
Name: snipolicy
Rule: client.ssl.client_hello.sni.contains("abc")
Action: pick_ca_group
UndefAction: Use Global
Hits: 0
Undef Hits: 0
Policy is bound to following entities
1) Bound to: CLIENTHELLO_REQ VSERVER v_SSL
Priority: 10set ssl vserver v_SSL -clientauth ENABLED -SNIEnable ENABLED
bind ssl vserver v_SSL -certkeyName snicert -sniCertsh ssl vserver v_SSL
Advanced SSL configuration for VServer v_SSL:
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED Ephemeral RSA: ENABLED Refresh Count: 0
Session Reuse: ENABLED Timeout: 120 seconds
Cipher Redirect: DISABLED
SSLv2 Redirect: DISABLED
ClearText Port: 0
Client Auth: ENABLED Client Cert Required: Mandatory
SSL Redirect: DISABLED
Non FIPS Ciphers: DISABLED
SNI: ENABLED
OCSP Stapling: DISABLED
HSTS: DISABLED
HSTS IncludeSubDomains: NO
HSTS Max-Age: 0
SSLv2: DISABLED SSLv3: ENABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED TLSv1.3: DISABLED
Push Encryption Trigger: Always
Send Close-Notify: YES
Strict Sig-Digest Check: DISABLED
Zero RTT Early Data: DISABLED
DHE Key Exchange With PSK: NO
Tickets Per Authentication Context: 1
ECC Curve: P_256, P_384, P_224, P_521
1) CertKey Name: snicert Server Certificate for SNI
Data policy
1) Policy Name: snipolicy Priority: 10
1) Cipher Name: DEFAULT
Description: Default cipher list with encryption strength >= 128bit
Configuration using the GUI
-
Navigate to Traffic Management > SSL > CA Certificates Group.
-
Click Add and specify a name for the group.
-
Click Create.
-
Select the CA certificate group and then click Show Bindings.
-
Click Bind.
-
In the CA Certificate Binding page, select an existing certificate or click Add to add a new certificate.
-
Click Select and then click Bind.
-
To bind another certificate, repeat steps 5 through 7.
-
Click Close.
-
In SSL Actions, click Add.
-
In Create SSL Action, specify a name for the action.
-
In Forward Action Virtual Server, select an existing virtual server or add a virtual server to forward the traffic to.
-
Optionally, set other parameters.
-
Click Create.
-
In SSL Policies, click Add.
-
In Create SSL Policy, specify a name for the policy.
-
In Action, select the action created earlier.
-
In Expression Editor, enter the rule to evaluate.
-
Click Create.
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Add or select a virtual server.
-
In Advanced Settings, click SSL Policies.
-
Click in the SSL Policy section.
-
In Select Policy, select the policy that you created earlier.
-
In Policy Binding, specify a priority for the policy.
-
In Type, select CLIENTHELLO_REQ.
-
Click Bind.
-
Click Done.
Unbind a CA certificate group by using the GUI
-
Navigate to Traffic Management > SSL > CA Certificates Group.
-
Select a certificate group and click Show Bindings.
-
Select the certificate to remove from the group and click Unbind.
-
If prompted for confirmation, click **Yes••.
-
Click Close.
Remove a CA certificate group by using the GUI
-
Navigate to Traffic Management > SSL > CA Certificates Group.
-
Select a certificate group and click Delete.
-
If prompted for confirmation, click Yes.