← Back to plugin index

Token Data Certificate Matcher

Description
Default implementation for certificate token lookup. This plugin tries to match the certificate in the token table of the persistency layer based on serial number, subject DN and issuer DN (all must match). This should be sufficient for most cases.
Type name
DefaultCertificateMatcher
Class
com.airlock.iam.core.misc.impl.authen.certificate.DefaultCertificateMatcher
May be used by
License-Tags
ClientCertificate
Properties
Token Data Provider (tokenDataProvider)
Description
Connection to the token data persistency layer.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Multi Format Dn Comparison (multiFormatDnComparison)
Description
If set to true, comparison of distinguished names (DNs) supports various formats. Specifically, the following DNs are considered to be equal:
  • a=A,b=B,c=C
  • c=C,b=B,a=A (backwards)
  • /a=A/b=B/c=C (slash notation)
  • /c=C/b=B/a=A (slash notation backwards)
  • a=A,b=B,x.y.z=C (where x.y.z is the OID for attribute c)
This is used if the tokens in the database are written by a different system than Airlock IAM which might use a different DB format.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: DefaultCertificateMatcher
id: DefaultCertificateMatcher-xxxxxx
displayName: 
comment: 
properties:
  multiFormatDnComparison: false
  tokenDataProvider: