This article describes how to configure certificate authentication such that username and password fields are not required for authentication.
Ensure that you install the client certificates on the client workstations that will be attempting to authenticate against the AAA virtual server.
To configure certificate authentication without using any other authentication policy, complete the following procedure:
Add a CA certificate on the AAA virtual server. CA must issue the client certificate to be used on the user side.
Click SSL Parameter.
Select Client Authentication as Mandatory.
Add an authentication policy on the AAA virtual server with authentication type as CERT.
Note: You can customize the expression or retain it as ns_true.
Note: If the requirement is to extract the user name and password from the client certificate, then set Two Factor as ON and select user name and group details from the subject and issuer fields in the certificate.
Bind this certificate authentication policy to the AAA virtual server.
Bind this AAA virtual server to the load balancing virtual server by specifying its FQDN in the Advance tab.
Import the client certificate on the browser.
Open the load balancing virtual server. A prompt with certificates appears.