Custom Headers

Matt Ward <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <VI1P193MB0749A502C04E2B471F7F31F2F4E20@VI1P193MB0749.EURP193.PROD.OUTLOOK.COM>
I am hoping this is a relatively straight forward question, but I have been struggling with it for some time and cannot find any examples online.

We are using ModSecurity 3.04 with NGINX and trying to get a custom header written to the audit log with every transaction. Essentially, we want to write the $ssl_client_s_dn_cn variable to the audit log which is populated by the users PKI certificate when they login through a reverse proxy. This info is set in a header to available to applications so if you had something similar to:

proxy_set_header ClientUsername $ssl_client_s_dn_cn.

How would you craft a modsec rule to write client username to the audit log?

Thanks in advance,

Matt

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.