Mutual-tls-by-proxy (Section)#

Path: /profiles/profile{id, type}/settings/authorization-server/dynamic-client-registration/non-templatized/mutual-tls-by-proxy

Allow mutual TLS to be terminated in a proxy instead of directly within the identity server

Parameters#

NameTypeRequiredDefaultDescription
trusted-issuersmulti-value, leafrefoptionalA list of client certificate issuers to trust with client registration.An empty list will mean all configured ssl client truststores.
useridstringoptionalUser ID credential that the proxy uses to authenticate using HTTP Basic authentication through a Proxy-Authorization header.
passwordnon-empty-stringoptionalPassword credential that the proxy uses to authenticate using HTTP Basic authentication through a Proxy-Authorization header.
client-certificate-http-headernon-empty-stringrequiredName of the HTTP header that the proxy uses to include the PEM- or base64-encoded DER representation of the client certificate in the forwarded request. Must be set for mutual-tls by-proxy to work.

Was this helpful?