Certificate authentication configuration task summary
All of the certificate authentication modes share a common set of configuration tasks. The delayed certificate authentication mode requires additional tasks.
To enable client-side certificate authentication in any of the supported modes:
- Enable certificate authentication
- Configuration of the certificate authentication mechanism
- Certificate login error page
When enabling delayed certificate authentication mode, complete the following additional tasks:
- Certificate login form
- Disable SSL session IDs for session tracking
- Enable and configure the Certificate SSL ID cache
- Set the timeout for Certificate SSL ID cache
- Error page for incorrect protocol
The WebSEAL server must be stopped and restarted to activate the new configuration settings.
To disable (unconfigure) client-side certificate authentication, complete the following tasks:
Technical notes for certificate authentication:
The WebSEAL configuration file settings for certificate authentication are summarized in the web reverse proxy Stanza Reference section.
Parent topic: Client-side certificate authentication