At a glance, nothing seem to indicate there is SSL client auth for TPS and LDAP user directory in the online doc, it is all about uid/pw auth, not SSL client auth, at: https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Certificate_System/8.1/h tml/Admin_Guide/configuring-tps.html Table 5.12. LDAP Authentication auth.instance.#.type The authentication type to use. This must be LDAP_Authentication.
We seem to have hardcoded uid/pwd authentication over SSL, no apparent SSL client auth seem to be supported at this moment, in:
SSL client auth support: ./base/tps/src/include/authentication/LDAP_Authentication.h
but uid/pwd auth in: ./base/tps/src/authentication/LDAP_Authentication.cpp
This will automatically get addressed when tps goes into the tomcat instance. I have already implemented client auth connection to the ds there, and its currently in place in IPA. Closing this ticket then,
Metadata Update from @nkinder: - Issue set to the milestone: 10.1 - 07/13 (July)
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/1065
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.