Authorizers are responsible for deciding if a request should be allowed or not. Options include HTTPS/TLS client certificate authentication, HTTP Basic Authentication, IP address restrictions, or using a reverse proxy.
For an overview of how authorization and authentication work in SignServer, see SignServer Authentication and Authorization.
To configure an Authorizer, define the property AUTHTYPE in your Worker as the fully-qualified name of the Authorizer. See Authorization Type Properties for more information.
By default (and if the property is not set), client-certificate authentication is required for a signature request to be processed. This can be changed using the AUTHTYPE property.
|
Property |
Description |
|---|---|
|
|
No authentication Sets the server to not require any authentication. |
|
|
Client certificate authentication Default value. Requires a certificate of all the clients. The certificates must be in the application server's truststore. Authorized clients is configured manually using the CLI interface. See Client Certificate Authorizer. |
|
|
Other authentication Provide the fully qualified class name of the Authorizer you want to use. |
Authorizer Types
See also SignServer Authentication and Authorization.