mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-08-09 09:51:49 +08:00
auto-select group when a certificate provides enough information
When a certificate contains a single group there is no need to request the user to select. Auto-select the group. Resolves: #692 Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
This commit is contained in:
+10
-1
@@ -189,9 +189,18 @@ possession of the corresponding private key.
|
||||
The certificate need also contain user identifying information,
|
||||
for example, the user ID of the client must be embedded in the certificate's
|
||||
Distinguished Name (DN), i.e., in the Common Name, or UID fields. For the
|
||||
server to read the name, the *cert-user-oid* configuration option
|
||||
server to read the user ID, the *cert-user-oid* configuration option
|
||||
must be set.
|
||||
|
||||
When *cert-group-oid* is configured the server extracts group names from the
|
||||
client certificate's DN and presents them for selection. If the client does
|
||||
not request a group and exactly one eligible group is present in the
|
||||
certificate — where eligible means either no *select-group* list is configured,
|
||||
or the group appears in the configured *select-group* list — the server
|
||||
automatically selects it and completes authentication without an extra round
|
||||
trip. If zero or more than one eligible groups are found the client is
|
||||
prompted to choose.
|
||||
|
||||
The following examples demonstrate how to use certtool from GnuTLS to
|
||||
generate such CA.
|
||||
|
||||
|
||||
@@ -407,6 +407,36 @@ REQ-AUTH-AUTH-005.
|
||||
**Links:** REQ-AUTH-INIT-002, REQ-AUTH-INIT-005, REQ-AUTH-AUTH-005,
|
||||
REQ-AUTH-AUTH-006, REQ-AUTH-AUTH-008
|
||||
|
||||
### REQ-AUTH-AUTH-041 — Worker auto-selects the certificate group when exactly one is eligible, avoiding an unnecessary group-selection prompt
|
||||
|
||||
**Requirement:** In `post_auth_handler()`, when `AUTH_TYPE_CERTIFICATE` is
|
||||
active, `ws->cert_groups_size > 0`, and the client did not request a group
|
||||
(no `group_list`/`group-select` field, no `select-group-by-url` match, and
|
||||
`default-select-group` not requested), the worker MUST NOT unconditionally
|
||||
respond with the "Please select your group." prompt. It MUST first compute
|
||||
the set of *eligible* certificate groups: if `select-group` is configured
|
||||
(`WSRCONFIG(ws)->n_group_list > 0`), eligible groups are the entries of
|
||||
`ws->cert_groups[]` that also appear in `WSRCONFIG(ws)->group_list[]`;
|
||||
otherwise (no `select-group` configured) every entry of `ws->cert_groups[]`
|
||||
is eligible. If exactly one eligible group exists, the worker MUST set
|
||||
`ws->groupname` to it and proceed with `SEC_AUTH_INIT` as if the client had
|
||||
requested that group, completing authentication without an extra round trip.
|
||||
If zero or more than one eligible groups exist, the "Please select your
|
||||
group." prompt (and the cert-group fallback of REQ-AUTH-AUTH-006) is
|
||||
unchanged.
|
||||
**Strength:** MUST
|
||||
**Status:** DERIVED
|
||||
**Source:** src/worker-auth.c:1730-1738
|
||||
**Acceptance:** positive, local — `cert-group-oid` configured, no
|
||||
`select-group` list, client certificate carries exactly one group (OU); a
|
||||
first POST with no `<group-select>` completes directly with
|
||||
`<auth id="success">` and a `Set-Cookie: webvpncontext=` header. Negative,
|
||||
local — client certificate carries multiple groups (OUs) and no
|
||||
`select-group` list is configured (or more than one of its groups matches a
|
||||
configured `select-group` list); a first POST with no `<group-select>` still
|
||||
yields "Please select your group." and no session cookie.
|
||||
**Links:** REQ-AUTH-AUTH-006, REQ-AUTH-AUTH-010
|
||||
|
||||
## AUTH — plain (`auth = plain[passwd=...,otp=...]`)
|
||||
|
||||
### REQ-AUTH-AUTH-011 — `plain[...]` requires at least one of `passwd=`/`otp=`; `vhost_init` fails closed without it
|
||||
|
||||
Reference in New Issue
Block a user