The Subject DN To User Attribute Certificate Mapper maps client certificates to user entries by looking for the certificate subject DN in a specified attribute of user entries.
The Subject DN To User Attribute Certificate Mapper component inherits from the Certificate Mapper
The properties supported by this managed object are as follows:
Basic Properties: | Advanced Properties: |
---|---|
description | None |
enabled | |
subject-attribute | |
user-base-dn |
Description | A description for this Certificate Mapper |
Default Value | None |
Allowed Values | A string |
Multi-Valued | No |
Required | No |
Admin Action Required | None. Modification requires no further action |
Description | Indicates whether the Certificate Mapper is enabled. |
Default Value | None |
Allowed Values | true false |
Multi-Valued | No |
Required | Yes |
Admin Action Required | None. Modification requires no further action |
Description | Specifies the name or OID of the attribute whose value should exactly match the certificate subject DN. |
Default Value | ds-certificate-subject-dn |
Allowed Values | The name or OID of an attribute type defined in the server schema. |
Multi-Valued | No |
Required | Yes |
Admin Action Required | None. Modification requires no further action |
Description | Specifies the base DNs that should be used when performing searches to map the client certificate to a user entry. |
Default Value | The server will perform the search in all public naming contexts. |
Allowed Values | A valid DN. |
Multi-Valued | Yes |
Required | No |
Admin Action Required | None. Modification requires no further action |
To list the configured Certificate Mappers:
dsconfig list-certificate-mappers [--property {propertyName}] ...
To view the configuration for an existing Certificate Mapper:
dsconfig get-certificate-mapper-prop --mapper-name {name} [--tab-delimited] [--script-friendly] [--property {propertyName}] ...
To update the configuration for an existing Certificate Mapper:
dsconfig set-certificate-mapper-prop --mapper-name {name} (--set|--add|--remove) {propertyName}:{propertyValue} [(--set|--add|--remove) {propertyName}:{propertyValue}] ...
To create a new Subject DN To User Attribute Certificate Mapper:
dsconfig create-certificate-mapper --mapper-name {name} --type subject-dn-to-user-attribute --set enabled:{propertyValue} [--set {propertyName}:{propertyValue}] ...
To delete an existing Certificate Mapper:
dsconfig delete-certificate-mapper --mapper-name {name}