CAC Authentication to LDAP User Repository
Has anyone been successful at getting CAC (client certificate) authentication working with an LDAP user repository?
I have a problem because our client certificate's websphere-supported properties do not have any exact match to any LDAP property. Are there any suggestions on what I should research on how to accomplish authentication?
We have an attribute which is very close, but not quite:
EVANS.DAVID.M.1234567890 (CAC's SubjectCN)
EVANS.DAVID.M.1234567890.C (LDAP name)
If we could just wildcard the .C off the end that would be fabulous since the CAC's SubjectCN is unique to a person, and we don't need to distinguish between types of people (contractor, civilian, reservist, etc.). I do not know why on earth the Air Force set LDAP up this way, but it seems that in any case it is little value added for a lot of pain. Are wildcards acceptable in a certificate filter? Any other ideas? THANKS!
-Dave
3 answers
Can you define what you mean by "CAC Proxy"?
The problem we are facing is that the RFC822_Name from the Subject Alternate Name(SAN) is the only value that is common in both the CAC and LDAP. IBM doesn't support parsing any value from the SAN, so we are hoping that this "CAC Proxy" will allow us to build a matching variable.
Can you describe how "CAC Proxy" would work?
Thanks for your insight.
Comments
Robert Carter
Apr 10 '14, 2:13 p.m.Dave Evans
Apr 10 '14, 2:32 p.m.Robert Carter
Apr 10 '14, 2:50 p.m.Dave Evans
Apr 10 '14, 3:23 p.m.