[drraw-users] drraw.conf mygetuser

Fabien Wernli wernli at in2p3.fr
Fri Sep 17 07:39:38 MDT 2010


Just for the record, we're using SSL and X.509 certificates and the sub
looks something like this:

sub mygetuser {
  if ($ENV{SSL_CLIENT_I_DN_O} eq "XYZ" &&
      $ENV{SSL_CLIENT_S_DN_O} eq "XYZ" &&
      $ENV{SSL_CLIENT_I_DN_C} eq "AB" &&
      $ENV{SSL_CLIENT_S_DN_C} eq "AB" &&
      $ENV{SSL_CLIENT_I_DN_CN} =~ /ABCDE/ &&
      $ENV{SSL_CLIENT_S_DN_OU} eq "IJKLM") {
    for (keys %users) {
      return $_ if $_ eq $ENV{'SSL_CLIENT_S_DN_CN'};
    }
  }
  return 'guest';
}




More information about the drraw-users mailing list