← Back to plugin index

Client Certificate (X.509) Request Authentication

Description

Authenticates single requests by their client certificate.

Warning 1: This authentication assumes that some external process can guarantee that the certificate belongs to the authenticating entity. This is typically done by challenging the entity to sign something with the corresponding private key. This is, for example, the case in an SSL handshake involving client certificate verification.

Warning 2: This authentication does not check whether the certificate was signed by a trusted entity. This must be done during the SSL handshake.

Type name
ClientCertificateRequestAuthentication
Class
com.airlock.iam.common.application.configuration.certificate.ClientCertificateRequestAuthenticationConfig
May be used by
Properties
User Attribute (userAttribute)
Description

Defines how the username is extracted from the certificate.

Usually the username is part of the DN (distinguished name) of the certified subject. This attribute specifies the attribute name of the username in the DN. Example: The value "cn" will extract the common name from the DN and use this as username.

The following values are interpreted separately:

  • dn: the whole distinguished name is used.
  • subjectAlternativeName: the alternative subject name is used.
  • certificate: the base64 encoded certificate.

Username transformation can be used to lookup the user based on a context-data field or to modify the extracted username (e.g. to strip the domain from the name).

Attributes
String
Mandatory
Suggested values
cn, sAMAccountName, dn, subjectAlternativeName, certificate
Check Validity Period (checkValidityPeriod)
Description
If enabled, the validity period of the certificate is checked. If disabled, expired (or not yet valid) certificates are also accepted.
Attributes
Boolean
Optional
Default value
true
Certificate Status Checkers (certStatusCheckers)
Description
A list of certificate status checkers used to check the revocation status of the client certificate. If more than one checker is configured, all of them are consulted and the certificate is considered revoked if at least one of them tells so.
Attributes
Plugin-List
Optional
Assignable plugins
User Store (userStore)
Description
If configured, the user is loaded from local persistence and checked for validity. Authentication fails if the user is not found or is invalid. If no user store is configured, no persistency look-up takes place and the authentication is performed on data contained within the credential only.
Attributes
Plugin-Link
Optional
Assignable plugins
Username Transformation (usernameTransformers)
Description
Transforms the provided username from the credential to a technical user ID.
Attributes
Plugin-List
Optional
Assignable plugins
Static Roles (staticRoles)
Description
Static list of roles granted to the authenticated user.
Attributes
String-List
Optional
Roles Blocklist (rolesBlocklist)
Description
List of role names that won't be granted to the authenticated user. The block list is also applied to persistent roles (if available).
Attributes
String-List
Optional
YAML Template (with default values)

type: ClientCertificateRequestAuthentication
id: ClientCertificateRequestAuthentication-xxxxxx
displayName: 
comment: 
properties:
  certStatusCheckers:
  checkValidityPeriod: true
  rolesBlocklist:
  staticRoles:
  userAttribute:
  userStore:
  usernameTransformers: