stunnel : user identification in mutual auth
Denis Polushin <[email protected]> Tue, 22 Oct 2019 21:22:22 +0300
| Newsgroups | gmane.network.stunnel.user |
|---|---|
| Message-ID | <CAN2rQM0+e5pHUzntSq-d=Xa3tYVAkC9Hoovx2vWzeZmxU3qH0w@mail.gmail.com> |
--===============3124564202371536568== Content-Type: multipart/alternative; boundary="0000000000005bdc74059583e2a8" --0000000000005bdc74059583e2a8 Content-Type: text/plain; charset="UTF-8" Hi All, Haven't found the answer for this issue. The scheme is : TLS-client <==tls==> stunnel-server <==open==> App-server In user session stunnel-server perform authorization for client with its certificate (verify=2) and send request further to App-server. How does App-server can identify user in this session? To grand permissions. Ideally it would be good to know CN or EKU of user certificate. Is it possible? Thanks a lot!! Denis --0000000000005bdc74059583e2a8 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto"><span style=3D"color:rgb(80,0,80);font-family:sans-serif;= font-size:12.8px">Hi All,</span><div dir=3D"auto" style=3D"color:rgb(80,0,8= 0);font-family:sans-serif;font-size:12.8px"><br></div><div dir=3D"auto" sty= le=3D"color:rgb(80,0,80);font-family:sans-serif;font-size:12.8px">Haven'= ;t found the answer for this issue.=C2=A0</div><div dir=3D"auto" style=3D"c= olor:rgb(80,0,80);font-family:sans-serif;font-size:12.8px"><br></div><div d= ir=3D"auto" style=3D"color:rgb(80,0,80);font-family:sans-serif;font-size:12= .8px">The scheme is :</div><div dir=3D"auto" style=3D"color:rgb(80,0,80);fo= nt-family:sans-serif;font-size:12.8px"><br></div><div dir=3D"auto" style=3D= "color:rgb(80,0,80);font-family:sans-serif;font-size:12.8px">TLS-client <= ;=3D=3Dtls=3D=3D> stunnel-server <=3D=3Dopen=3D=3D> App-server</di= v><div dir=3D"auto" style=3D"color:rgb(80,0,80);font-family:sans-serif;font= -size:12.8px"><br></div><div dir=3D"auto" style=3D"color:rgb(80,0,80);font-= family:sans-serif;font-size:12.8px">In user session stunnel-server perform = authorization for client with its certificate (verify=3D2) and send request= further to App-server.</div><div dir=3D"auto" style=3D"color:rgb(80,0,80);= font-family:sans-serif;font-size:12.8px"><br></div><div dir=3D"auto" style= =3D"color:rgb(80,0,80);font-family:sans-serif;font-size:12.8px">How does Ap= p-server can identify user in this session? To grand permissions. Ideally i= t would be good to know CN or EKU of user certificate. Is it possible?</div= ><div dir=3D"auto" style=3D"color:rgb(80,0,80);font-family:sans-serif;font-= size:12.8px"><br></div><div dir=3D"auto" style=3D"color:rgb(80,0,80);font-f= amily:sans-serif;font-size:12.8px">Thanks a lot!!</div><div dir=3D"auto" st= yle=3D"color:rgb(80,0,80);font-family:sans-serif;font-size:12.8px">Denis</d= iv></div> --0000000000005bdc74059583e2a8-- --===============3124564202371536568== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ stunnel-users mailing list [email protected] https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users --===============3124564202371536568==--