stunnel : user identification in mutual auth

Denis Polushin <[email protected]> Tue, 22 Oct 2019 21:22:22 +0300
Newsgroups gmane.network.stunnel.user
Message-ID <CAN2rQM0+e5pHUzntSq-d=Xa3tYVAkC9Hoovx2vWzeZmxU3qH0w@mail.gmail.com>
--===============3124564202371536568==
Content-Type: multipart/alternative; boundary="0000000000005bdc74059583e2a8"

--0000000000005bdc74059583e2a8
Content-Type: text/plain; charset="UTF-8"

Hi All,

Haven't found the answer for this issue.

The scheme is :

TLS-client <==tls==> stunnel-server <==open==> App-server

In user session stunnel-server perform authorization for client with its
certificate (verify=2) and send request further to App-server.

How does App-server can identify user in this session? To grand
permissions. Ideally it would be good to know CN or EKU of user
certificate. Is it possible?

Thanks a lot!!
Denis

--0000000000005bdc74059583e2a8
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><span style=3D"color:rgb(80,0,80);font-family:sans-serif;=
font-size:12.8px">Hi All,</span><div dir=3D"auto" style=3D"color:rgb(80,0,8=
0);font-family:sans-serif;font-size:12.8px"><br></div><div dir=3D"auto" sty=
le=3D"color:rgb(80,0,80);font-family:sans-serif;font-size:12.8px">Haven&#39=
;t found the answer for this issue.=C2=A0</div><div dir=3D"auto" style=3D"c=
olor:rgb(80,0,80);font-family:sans-serif;font-size:12.8px"><br></div><div d=
ir=3D"auto" style=3D"color:rgb(80,0,80);font-family:sans-serif;font-size:12=
.8px">The scheme is :</div><div dir=3D"auto" style=3D"color:rgb(80,0,80);fo=
nt-family:sans-serif;font-size:12.8px"><br></div><div dir=3D"auto" style=3D=
"color:rgb(80,0,80);font-family:sans-serif;font-size:12.8px">TLS-client &lt=
;=3D=3Dtls=3D=3D&gt; stunnel-server &lt;=3D=3Dopen=3D=3D&gt; App-server</di=
v><div dir=3D"auto" style=3D"color:rgb(80,0,80);font-family:sans-serif;font=
-size:12.8px"><br></div><div dir=3D"auto" style=3D"color:rgb(80,0,80);font-=
family:sans-serif;font-size:12.8px">In user session stunnel-server perform =
authorization for client with its certificate (verify=3D2) and send request=
 further to App-server.</div><div dir=3D"auto" style=3D"color:rgb(80,0,80);=
font-family:sans-serif;font-size:12.8px"><br></div><div dir=3D"auto" style=
=3D"color:rgb(80,0,80);font-family:sans-serif;font-size:12.8px">How does Ap=
p-server can identify user in this session? To grand permissions. Ideally i=
t would be good to know CN or EKU of user certificate. Is it possible?</div=
><div dir=3D"auto" style=3D"color:rgb(80,0,80);font-family:sans-serif;font-=
size:12.8px"><br></div><div dir=3D"auto" style=3D"color:rgb(80,0,80);font-f=
amily:sans-serif;font-size:12.8px">Thanks a lot!!</div><div dir=3D"auto" st=
yle=3D"color:rgb(80,0,80);font-family:sans-serif;font-size:12.8px">Denis</d=
iv></div>

--0000000000005bdc74059583e2a8--

--===============3124564202371536568==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
stunnel-users mailing list
[email protected]
https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users

--===============3124564202371536568==--