HTTP Request mTLS Client Certificate Extractor
Description
Extracts the mutual TLS (mTLS) client certificate of the incoming HTTP request.
The plugin allows certificates to be extracted from various request headers.
May be used by
Properties
HTTP Header Name (
httpHeaderName) Description
HTTP header name whose value contains the mTLS X.509 client certificate.
The HTTP header name must be identical to the configured HTTP header name on the proxy in front of IAM. HTTP header names are case-insensitive. The first value of the first header received is considered. The received header value is extracted using the configured extraction format.
The HTTP header name consists of any visible ASCII characters except delimiters "(),/:;<=>?@[\]{}".
Attributes
String
Optional
Validation RegEx: [a-zA-Z0-9!#$%&'*+\-.^_`|~]+
Default value
X-Forwarded-mTLS-Client-Cert
Example
X-Forwarded-mTLS-Client-Cert
Example
X-SSL-Client-Cert
Example
x-forwarded-client-cert
Extraction Format (
extractionFormat) Description
Defines the expected format that the mTLS X.509 client certificate is provided in the specified HTTP header.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)
type: RequestMtlsClientCertificateExtractor
id: RequestMtlsClientCertificateExtractor-xxxxxx
displayName:
comment:
properties:
extractionFormat:
httpHeaderName: X-Forwarded-mTLS-Client-Cert