Forum Discussion

Joe_5599_134300's avatar
Joe_5599_134300
Icon for Nimbostratus rankNimbostratus
Feb 22, 2019

OCSP validation with SHA1, SHA256 hash signed client certificates

I need to be able to check client SSL certificates for either SHA1 or SHA256 hash then send to either SHA1 or SHA256 OCSP responder pools. Currently have this working ok with APM policy with either single OCSP responder pool at a time. Would like to have working with where APM can make the decision to send client cert validation traffic to OCSP responder SHA1 or SHA256. Not sure if this can be done with additional APM OCSP fields or if I need an irule to run first.