Menu

#9 Verify X.509 subject/user against factor

open
nobody
None
5
2012-09-13
2010-01-26
No

Today if using X.509 authentication the subject DN / extracted username is not verified through a factor. Instead cosign relies on the web server to perform this verification. Usually this is solely based on the certificate chain.

It would be benefitial if the subject DN or better extracted username could be verified through a factor. This way a factor could be used to verify if the user for which the certificate was issued really exists in a directory (e.g. LDAP / AD) and if the account is locked.

Discussion

Anonymous
Anonymous

Add attachments
Cancel





Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.