Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Note added for docker
Info

This article is valid for Smart ID 20.11 and later.

This article describes how to set up certificate-based login to Smart ID Identity Manager.

Note

Not yet supported for docker. The article is only relevant for WAR file deployment.

Prerequisites

Expand
titlePrerequisites

A working HTTPS configuration with client authentication on the Tomcat is required. See Configure https for Tomcat.

...

Expand
titleSet up authentication profile

The first step is to set up an authentication profile in Identity Manager Admin:

  1. Follow the instructions in Set up authentication profile in Identity Manager, to set up an authentication profile of any of the following types:
    • Client Certificate and LDAP
    • Client Certificate and Core Object
    • Client Certificate Internal - not recommended in a production environment
  2. Select the certificate attribute the system shall extract the login information from.
    • User Principal Name (UPN): Extracts the information from the SANAttribute "otherName"
    • SAN Email (RFC822Name): Extracts the information from the SANAttribute "rfc822Name"
    • Subject CN: Extracts the information from the CN field
    • Subject Email: Extracts the information from the EMAILADDRESS field

...