How to get the certificate into the X509 filter (Spring Security)?

前端 未结 2 463
無奈伤痛
無奈伤痛 2021-01-22 12:21

I need to extract more information than just the CN of the certificate. Currently, I only get the standard UserDetails loadUserByUsername(String arg) where arg is the CN of the

相关标签:
2条回答
  • 2021-01-22 12:49

    No you can't get it that way. You need to grab it from the HttpServletRequest:

    X509Certificate[] certs = (X509Certificate[])HttpServletRequest.getAttribute("javax.servlet.request.X509Certificate");
    
    0 讨论(0)
  • 2021-01-22 12:52

    It is also worth noting that once you are authorized by the in-built X509AuthenticationFilter of Spring Security as it has accepted your certificate, then you can access the X509Certificate as

    Object object = SecurityContextHolder.getContext().getAuthentication().getCredentials();
    if (object instanceof X509Certificate)
    {
        X509Certificate x509Certificate = (X509Certificate) object;
        //convert to bouncycastle if you want
        X509CertificateHolder x509CertificateHolder =
            new X509CertificateHolder(x509Certificate.getEncoded());
        ...
    
    0 讨论(0)
提交回复
热议问题