← Back to plugin index

OAuth 2.0 Client Certificate

Description
Defines a certificate which can be used during the client authentication in OAuth 2.0.
Type name
OAuth2ClientCertificate
Class
com.airlock.iam.oauth2.application.configuration.clientauthentication.OAuth2ClientCertificateConfig
May be used by
License-Tags
OAuthServer
Properties
Subject DN (subjectDN)
Description
The subject distinguished name of of the certificate in the comma separated format, e.g. "CN=John Smith,OU=Marketing,O=Company,C=CH".

For RDN types without a string representation defined, the OID format with values starting with a '#', followed by the hexadecimal representation, must be used (see RFC 2253. An example of such a value in OID notation would be 1.3.6.1.4.1.1466.0=#04024869 (OCTET String value "Hi" for OID 1.3.6.1.4.1.1466.0).

OpenSSL can be used to extract the subject as follows:

openssl x509 -in cert.pem -noout -subject -nameopt sep_comma_plus -nameopt dn_rev -nameopt utf8

if this produces an error the subject should be configured with the RDNs in their OID's and hexadecimal values as mentioned above. This format can be generated by:

openssl x509 -in cert.pem -noout -subject -nameopt dump_all -nameopt dump_der -nameopt oid -nameopt sep_comma_plus
Attributes
String
Mandatory
Issuer DN (issuerDN)
Description
The optional issuer distinguished name of of the certificate in the comma separated format, e.g. "CN=Company Trusted Root,O=Company,C=CH". If defined, this value is also used to compare the certificates during the authentication.

For RDN types without a string representation defined, the OID format with values starting with a '#', followed by the hexadecimal representation, must be used (see RFC 2253. An example of such a value in OID notation would be 1.3.6.1.4.1.1466.0=#04024869 (OCTET String value "Hi" for OID 1.3.6.1.4.1.1466.0).

OpenSSL can be used to extract the issuer as follows:

openssl x509 -in cert.pem -noout -issuer -nameopt sep_comma_plus -nameopt dn_rev -nameopt utf8

if this produces an error the issuer should be configured with the RDNs in their OID's and hexadecimal values as mentioned above. This format can be generated by:

openssl x509 -in cert.pem -noout -issuer -nameopt dump_all -nameopt dump_der -nameopt oid -nameopt sep_comma_plus
Attributes
String
Optional
YAML Template (with default values)

type: OAuth2ClientCertificate
id: OAuth2ClientCertificate-xxxxxx
displayName: 
comment: 
properties:
  issuerDN:
  subjectDN: