Forum Discussion
TJ_Vreugdenhil
Apr 09, 2013Cirrus
I got this to work using the following:
set X509_subject [substr [X509::subject [SSL::cert 0]] 3 ","]
log local0. "X509-subject-CN:$X509_subject"
if { ! ( [class match $X509_subject equals CLASS-1 ] || [class match $X509_subject equals CLASS-2] ) } {
log local0. "Client dropped :$X509_subject"
drop