-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
Edit: I can see the The Whole Certificate and Only the Whole Certificate section so feel free to ignore this if there's no interest in defining the individual certification information headers.
This comes from evaluating this for an RFC8705 implementation, which, contrary to what the main body currently says does not need the full certificate value - its SHA256 fingerprint is enough for self_signed_tls_client_auth and token constraining.
It is, unfortunately, not the case that all proxies allow to access the whole certificate as a value. Plus when they do they may encode it differently (e.g. caddy escapes the cert?).
It'd be great, given this draft would move forward, to also think about individual useful "component" headers.
e.g.
Client-Cert-Fingerprint-SHA256Client-Cert-Fingerprint-SHA1Client-Cert-SubjectDNClient-Cert-SAN-*- etc.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels