Credential Data Certificate Matcher
Description
The plugin extracts a username from a X509 client certificate. The extracted username can afterwards be used by e.g. an authenticator.
A certificate contains the following DN:
The matcher can be configured (without User Iterator) to match the CN as user attribute, therefore, the extracted username is "test".
In a first step, a user identifier is extracted from the certificate data (e.g. from the subject DN). The result can either be used directly as username, or additionally, a User Iterator is configured to match the extracted identifier against some user attribute. If a matching user is found, its username is returned.
Example:A certificate contains the following DN:
cn=test,ou=local,o=company,c=ch.The matcher can be configured (without User Iterator) to match the CN as user attribute, therefore, the extracted username is "test".
May be used by
Properties
User Attribute (
userAttribute) Description
Defines how the user's username (or other piece of data used to look up the username) is to be extracted from the certificate. Example: The value "cn" will extract the common name from the DN and use it as username.
The following value is treated specially:
- "altSubjectName": Use the certificate's alternative subject name as username.
Attributes
String
Mandatory
Suggested values
cn, altSubjectName
Username Transformer (
usernameTransformer) Description
Transforms the extracted username from the certificate before it is used in the lookup.
Attributes
Plugin-Link
Optional
Assignable plugins
User Iterator (
userIterator) Description
Searches the user in the underlying persistency layer by using the extracted user attribute and returns its username. If no iterator is configured, the extracted (and eventually transformed) user attribute is used as username.
Attributes
Plugin-Link
Optional
Assignable plugins
Context Data Columns (
contextDataColumns) Description
Defines the values the extracted user attribute is matched against in the lookup. The value must match any of the context columns.
Attributes
String-List
Optional
YAML Template (with default values)
type: CredentialDataCertificateMatcher
id: CredentialDataCertificateMatcher-xxxxxx
displayName:
comment:
properties:
contextDataColumns:
userAttribute:
userIterator:
usernameTransformer: