-
Feature Request
-
Resolution: Unresolved
-
Major
-
None
-
None
-
False
-
-
False
-
Not Started
-
Not Started
-
Not Started
-
Not Started
-
Not Started
-
Not Started
-
-
-
RHOAM Sprint 63, RHOAM Sprint 64, RHOAM Sprint 65
Because APIcast has `ssl_verify_client optional_no_ca;`, it will always request Client Certificates. Normally this behavior is fine, but in the case that the API is used to serve a frontend application, it results in browsers always prompting the user to select a Client Certificate if they have ANY client certificates configured when browsing to the service. In this scenario it would be useful to make this option configurable.
Developer Notes:
Because this option was specifically selected to support the TLS Client Certificate policy [1], changing this setting may make the gateway incompatible with this policy so a proper warning should be in place. Similar to our "path routing is not compatible with TLS" [2] message.
- documents
-
THREESCALE-11404 Support Client Certificate revocation in APIcast
-
- To Document
-
- links to
-
RHEA-2025:146559 Red Hat 3scale API Management 2.16.0 Release - Container Images
- mentioned on