Client Certificate (X.509) Request Authentication
Authenticates single requests by their client certificate.
Warning 1: This authentication assumes that some external process can guarantee that the certificate belongs to the authenticating entity. This is typically done by challenging the entity to sign something with the corresponding private key. This is, for example, the case in an SSL handshake involving client certificate verification.
Warning 2: This authentication does not check whether the certificate was signed by a trusted entity. This must be done during the SSL handshake.
userAttribute) Defines how the username is extracted from the certificate.
Usually the username is part of the DN (distinguished name) of the certified subject. This attribute specifies the attribute name of the username in the DN. Example: The value "cn" will extract the common name from the DN and use this as username.
The following values are interpreted separately:
- dn: the whole distinguished name is used.
- subjectAlternativeName: the alternative subject name is used.
- certificate: the base64 encoded certificate.
Username transformation can be used to lookup the user based on a context-data field or to modify the extracted username (e.g. to strip the domain from the name).
checkValidityPeriod) certStatusCheckers) userStore) usernameTransformers) staticRoles) rolesBlocklist)
type: ClientCertificateRequestAuthentication
id: ClientCertificateRequestAuthentication-xxxxxx
displayName:
comment:
properties:
certStatusCheckers:
checkValidityPeriod: true
rolesBlocklist:
staticRoles:
userAttribute:
userStore:
usernameTransformers: