← Back to plugin index

Client Certificate XFCC Format

Description
The mTLS client certificate is expected in XFCC (x-forwarded-client-cert) header format as specified by Envoy proxy.

The XFCC is a proxy header which indicates certificate information of part or all of the clients or proxies that a request has flowed through, on its way from the client to the server.

IAM requires that the Cert key is set in the XFCC header under which the URL encoded PEM certificate is contained.

Envoy and other proxies in between, e.g. Airlock Micogateway, must be configured accordingly.

If an invalid format is presented, the certificate cannot be extracted.

Type name
ClientCertificateXfccExtractionFormat
Class
com.airlock.iam.common.application.configuration.gateway.extractor.ClientCertificateXfccExtractionFormatConfig
May be used by
Properties
YAML Template (with default values)

type: ClientCertificateXfccExtractionFormat
id: ClientCertificateXfccExtractionFormat-xxxxxx
displayName: 
comment: 
properties: