You can use the ssl-enforcement
policy to filter incoming SSL requests. It allows you to restrict or
allow access only to requests with client certificate authentication or only to a subset of valid clients.
This policy is mainly used in plan configuration to allow access to consumers for a given set of certificates.
Property | Required | Description | Type | Default |
---|---|---|---|---|
requiresSsl |
- |
Is SSL requires to access this resource? |
boolean |
true |
requiresClientAuthentication |
- |
Is client authentication required to access this resource? |
boolean |
false |
whitelistClientCertificates |
- |
List of allowed X.500 names (from client certificate) |
array of strings |
- |
"ssl-enforcement" : {
"requiresSsl": true,
"requiresClientAuthentication": true,
"whitelistClientCertificates": [
"CN=localhost,O=GraviteeSource,C=FR"
]
}
Code | Message |
---|---|
|
Access to the resource is unauthorized according to policy rules |
|
Access to the resource is forbidden according to policy rules |
You can use the response template feature to override the default responses provided by the policy. These templates must be defined at the API level (see the API Console Response Templates option in the API Proxy menu).