Hi F5 Team,
We came across scenarios where certain Applications expect the fingerpint of the Client Certificate itself to be included into the HTTP header. As of now, the F5 Distributed SaaS WAF doesn't quite support this functionality, other parts of the TLS session such as the client certificate serial number can be included into an upstream HTTP header, but not a computed fingerprint. Unfortunately, due to strict protocol requirements from the Application(s), there's no room for modification.
Akamai, AWS CloudFront, AWS ALB & a few others already support this feature. Would be good for F5 Team to investigate & add this feature for customers benefit.
HTTP header options that are currently supported by F5 SaaS WAF are listed in this Article:- https://my.f5.com/manage/s/article/K000147216
Thanks,