# Inserting the client certificate in a header

**URL:** <https://community.a10networks.com/t/inserting-the-client-certificate-in-a-header/193>\
**Category:** aFleX\
**Created:** [January 21, 2013, 2:33pm UTC](https://community.a10networks.com/t/inserting-the-client-certificate-in-a-header/193 "2013-01-21T14:33:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mischa](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mischa](https://community.a10networks.com/u/mischa)\
**Post date:** [January 21, 2013, 2:33pm UTC](https://community.a10networks.com/t/inserting-the-client-certificate-in-a-header/193/1 "2013-01-21T14:33:33Z")

</div>

When you need the client certificate on the real server:

`when CLIENTSSL\_CLIENTCERT { set cert [SSL::cert 0] session add ssl [SSL::sessionid] $cert }

when HTTP\_REQUEST { set cert [session lookup ssl [SSL::sessionid]] regsub -all {([\-]+(BEGIN|END) CERTIFICATE[\-]+)|\n} [X509::whole $cert] {} chdr HTTP::header insert CLIENT\_CERT $chdr }`

---

<div class="post-metadata">

**Author:** ![mischa](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mischa](https://community.a10networks.com/u/mischa)\
**Post date:** [March 22, 2013, 2:39pm UTC](https://community.a10networks.com/t/inserting-the-client-certificate-in-a-header/193/2 "2013-03-22T14:39:31Z")

</div>

Slightly modified version without the persistency table:

`when CLIENTSSL\_CLIENTCERT { set cert [SSL::cert 0] }

when HTTP\_REQUEST { regsub -all {([\-]+(BEGIN|END) CERTIFICATE[\-]+)|\n} [X509::whole $cert] {} chdr HTTP::header insert X-CLIENT-CERT $chdr }`

---

<div class="post-metadata">

**Author:** ![mischa](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mischa](https://community.a10networks.com/u/mischa)\
**Post date:** [October 11, 2013, 3:03pm UTC](https://community.a10networks.com/t/inserting-the-client-certificate-in-a-header/193/3 "2013-10-11T15:03:41Z")

</div>

Other alternative `when HTTP_REQUEST {`  
`set cert [X509::whole [SSL::cert 0]]`  
`regsub -all {\n|-----BEGIN CERTIFICATE-----|-----END CERTIFICATE-----} $cert "" newcert`  
`HTTP::header insert "X-Client-SSL-Cert" $newcert }`
