NextGenPSD2 Certificate Authenticator
Description
Certificate authenticator for PSD2 QWACs (Qualified Website Authentication Certificates).
If the certificate passes all of the configured validity checks, the resulting authenticated technical user will contain the following elements from the certificate:
- The subject DN's organizationIdentifier (oid 2.5.4.97 according to ITU-T Recommendations X.520) as the username.
- The payment service roles contained in the QCStatement (RFC 3739) with ID "0.4.0.19495.2" as granted user roles. The roles can be one of: PSP_AS, PSP_PI, PSP_AI or PSP_IC.
Technical clients are inserted into the configured persistence. A technical client is identified by the certificate's subject DN and will have the organizationIdentifier as display name. A TPP therefore can have multiple technical clients.
This plugin must not be used in other locations than in a HTTP Request Authentication (using Airlock Gateway One-Shot Flow).
May be used by
Properties
Client Repository (
clientRepository) Description
The technical client repository to implicitly register technical clients.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Technical Client Interceptors (
interceptors) Description
Defines interceptors that get notified upon changes on technical clients.
Attributes
Plugin-List
Optional
Assignable plugins
Check Validity Period (
checkValidityPeriod) Description
If enabled, the validity period of the certificate is checked. If disabled, expired (or not-yet-valid) certificates are also accepted.
Attributes
Boolean
Optional
Default value
true
Certificate Status Checkers (
certStatusCheckers) Description
A list of certificate status checkers used to check the revocation status of the client certificate. If more than one checker is configured, all of them are consulted and the certificate is considered revoked if at least one of them tells so.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)
type: NextGenPsd2CertificateAuthenticator
id: NextGenPsd2CertificateAuthenticator-xxxxxx
displayName:
comment:
properties:
certStatusCheckers:
checkValidityPeriod: true
clientRepository:
interceptors: