← Back to plugin index

Client Certificate Context Extractor

Description

Context extractor that determines the context by matching configurable regular expressions against information in the client certificate extracted from the request.

This extractor works in conjunction with client certificate authentication.

Type name
ClientCertificateContextExtractor
Class
com.airlock.iam.common.application.configuration.context.ClientCertificateContextExtractor
May be used by
Properties
Mappings (mappings)
Description

Defines mappings of regular expressions patterns to configuration contexts.

Each pattern is matched in order against the issuer distinguished name (DN) of the extracted client certificate.

The first matching pattern determines the resulting configuration context.

Attributes
Plugin-List
Mandatory
Assignable plugins
Match Against Subject DN (matchAgainstSubjectDn)
Description
By default, the patterns are matched against the distinguished name (DN) of the certificate issuer. If this property is enabled, the patterns are matched against the DN of the certificate subject (holder) instead.
Attributes
Boolean
Optional
Default value
false
Fallback Context (fallbackContext)
Description
Name of the context to be used if no pattern matches or no client certificate could be extracted from the request.
Leave empty to implicitly use the default context. If this plugin is used within a "Combining Context Extractor", use "[DEFAULT]" to explicitly return the default context if necessary.
Attributes
String
Optional
Example
CTX1
Example
EXT
Example
[DEFAULT]
Gateway (gateway)
Description
Settings regarding an Airlock Gateway or Airlock Microgateway reverse proxy placed in front of Airlock IAM.

The client certificate is extracted differently from the request based on this configuration:

  • Airlock Gateway (WAF): certificate is extracted from the environment cookie
  • Airlock Microgateway: certificate is extracted from the configured header
  • When no gateway is configured, attempt to extract the client certificate from the jakarta.servlet.request.X509Certificate request attribute

Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: ClientCertificateContextExtractor
id: ClientCertificateContextExtractor-xxxxxx
displayName: 
comment: 
properties:
  fallbackContext:
  gateway:
  mappings:
  matchAgainstSubjectDn: false