← Back to plugin index

Certificate Data Extractor Task

Description
This task plug-in iterates over user or credential records reads an X509 certificate(or the TBS part of it) from the record, extracts information (e.g. DN or serial number) from it and stores this information in another field of the record.

This task can be used to retrieve information encoded in the certificate and write it to the user record so the information can be used in search criteria, queries or be displayed more easily in the admin tool.

The certificate data read from the record must be the base-64 encoded binary representation of an X.509 ASN.1 structure. It also can be only the TBS-part ("to-be-signed part") of the certificate.

Type name
CertificateDataExtractorTask
Class
com.airlock.iam.servicecontainer.app.application.configuration.task.CertificateDataExtractorTask
May be used by
License-Tags
ClientCertificate
Properties
Credential Persister (credentialPersister)
Description
The credential persister plug-in is used to read the certificate and store the extracted piece(s) of information.

The returned credentials must either contain the certificate data in the string credential field or in one of the context data fields. In the latter case, the name of the context data field containing the certificate data must be specified in property "certificate-property".

Make sure the persister is able to store the target field(s), i.e. the field(s) where the extracted data is stored. It is usally necessary to list these fields in the context data container.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Credential Iterator (credentialIterator)
Description
The credential iterator plug-in used to iterate over a set of credential structures. For efficiency reasons it makes sense to limit the set of credential structures returned by this plug-in as much as possible.

It is usually a good idea to already include a "not-null"-check on the certificate data and "null"-checks in the fields where the extracted data is stored. Like this only the records with missing (i.e. not yet processed) data are processed.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Certificate Property (certificateProperty)
Description
Name of the data field of the context data container to read the certificate data from. If this property is not defined, the certificate data is read from the string credential data field of the configured credential persister.
Attributes
String
Optional
Suggested values
cert_x509_data, cert_tbs, client_certificate
Is Tbs Data (isTbsData)
Description
Set to true if the stored certificate data is not an X509 certificate but only the TBS-part (to-be-signed-part) of it.
Attributes
Boolean
Optional
Default value
false
Mapping (mapping)
Description
Mappings of certificate data elements to context data properties.
Attributes
Plugin-List
Mandatory
Assignable plugins
YAML Template (with default values)

type: CertificateDataExtractorTask
id: CertificateDataExtractorTask-xxxxxx
displayName: 
comment: 
properties:
  certificateProperty:
  credentialIterator:
  credentialPersister:
  isTbsData: false
  mapping: