OAuth 2.0 Client Certificate
subjectDN) For RDN types without a string representation defined, the OID format with values starting with a '#', followed by the hexadecimal representation, must be used (see RFC 2253. An example of such a value in OID notation would be 1.3.6.1.4.1.1466.0=#04024869 (OCTET String value "Hi" for OID 1.3.6.1.4.1.1466.0).
OpenSSL can be used to extract the subject as follows:
openssl x509 -in cert.pem -noout -subject -nameopt sep_comma_plus -nameopt dn_rev -nameopt utf8
if this produces an error the subject should be configured with the RDNs in their OID's and hexadecimal values as mentioned above. This format can be generated by:
openssl x509 -in cert.pem -noout -subject -nameopt dump_all -nameopt dump_der -nameopt oid -nameopt sep_comma_plus issuerDN) For RDN types without a string representation defined, the OID format with values starting with a '#', followed by the hexadecimal representation, must be used (see RFC 2253. An example of such a value in OID notation would be 1.3.6.1.4.1.1466.0=#04024869 (OCTET String value "Hi" for OID 1.3.6.1.4.1.1466.0).
OpenSSL can be used to extract the issuer as follows:
openssl x509 -in cert.pem -noout -issuer -nameopt sep_comma_plus -nameopt dn_rev -nameopt utf8
if this produces an error the issuer should be configured with the RDNs in their OID's and hexadecimal values as mentioned above. This format can be generated by:
openssl x509 -in cert.pem -noout -issuer -nameopt dump_all -nameopt dump_der -nameopt oid -nameopt sep_comma_plus
type: OAuth2ClientCertificate
id: OAuth2ClientCertificate-xxxxxx
displayName:
comment:
properties:
issuerDN:
subjectDN: