revision 3b2140880492f615f084b3b75c888c1631f06cfc
authentication=Authentication Modules
CERTex=Unknown Certificate Authority.
CertNoContext=Unable to set up LDAP context.
CertExpired=Certificate Has Expired.
CertVerifyFailed=Could not verify certificate.
CertNoReg=Error locating registered certificate.
CertRevoked=Certificate has been revoked.
iCertNotValidYet=Certificate is not yet valid.
CertIsNotValid=Certificate is not valid.
a101=Match Certificate in LDAP client certificate must exist in the directory for the authentication to be successful.
a1011=Subject DN Attribute Used to Search LDAP for Certificates is the attribute used to search the directory for the certificate Certificate module will search the directory for the certificate using the search filter based on this attribute \
and the value of the Subject DN taken from the certificate.
a102=Match Certificate to CRL Client Certificate will be checked against the Certificate Revocation list held in the directory Certificate Revocation List can be provisioned into the directory. Having this option enabled will cause all client \
certificates to be checked against this list.
a1023=Match CA Certificate to CRL CA certificate that issued the client certificate will also be checked against the CRL.
a1024=Cache CRLs in memory CRLs will be cached in memory
a1025=Update CA CRLs from CRLDistributionPoint new CA CRLs from CRLDistributionPoint and update it in Directory Server the CA certificate includes an IssuingDistributionPoint or has an CRLDistributionPoint extension set \
OpenAM tries to update the CRLs if neeed (i.e. CRL is out-of-date). <br/>This property controls if the update should be performed.<br/>\
This property is only used if CA CRL checking is enabled.
a1021=Issuer DN Attribute(s) Used to Search LDAP for CRLs is the name of the attribute taken from the CA certificate that will be used to search the CRL. only one attribute name is specified, the ldap searchfilter will be (attrName=Value_of_the_corresponding_Attribute_from_SubjectDN)<br/>\
e.g. SubjectDN of issuer cert 'C=US, CN=Some CA, serialNumber=123456',attribute name specified is 'CN', searchfilter used will be <code>(CN=Some CA)</code><br/><br/>\
If serveral attribute names are specified, they have to separated by <code>,</code>. The resulting ldap searchfilter value will \
be a comma separated list of name attribute values, the search attribute will be <code>cn</code><br/>\
e.g. SubjectDN of issuer cert 'C=US, CN=Some CA, serialNumber=123456',attribute names specified are 'CN,serialNumber', searchfilter used will be \
<code>cn=CN=Some CA,serialNumber=123456</code><br/>\
The order of the values of the attribute names matter as they must match the value of the <code>cn</code> attribute of a crlDistributionPoint entry in the directory server.
a1022=HTTP Parameters for CRL Update parameters will be included in any HTTP CRL call to the Certificate Authority the Client or CA certificate contains the Issuing Distribution Point Extension then OpenAM will use this information \
to retrieve the CRL from the distribution point. This property allow custom HTTP parameters to be included in the CRL request.<br/><br/>\
The format of the parameter is as follows:<br/><br/>\
a103=OCSP Validation Online Certificate Status Protocol validation for OCSP aware certificates the certificate contains OCSP validation information then OpenAM will use this information to check the validity \
of the certificate as part of the authentication process.<br/><br/>\
<i>NB </i>The OpenAM server must have Internet connectivity for OCSP to work
a104=LDAP Server Where Certificates are Stored this list to set the LDAP server used to search for certificates. Certificate authentication module will use this list for the LDAP server used to search for certificates. A single entry \
must be in the format:<br/><br/><code>ldap_server:port</code><br/><br/>Multiple entries allow associations between OpenAM servers and a \
LDAP server. The format is:<br/><br/><code>local server name | server:port</code><br/><br/>\
The local server name is the full name of the server from the list of servers and sites.
a105=LDAP Search Start or Base DN start point in the LDAP server for the certificate search entering multiple entries, each entry must be prefixed with a local server name. Multiple entries allow different \
search Base DNs depending on the OpenAM server in use. The format is:<br/><br/><code>local server name | base dn</code><br/><br/>\
The local server name is the full name of the server from the list of servers and sites.
# unused
a106=LDAP Access Authentication Type
a107=LDAP Server Authentication User of the user used by the module to authenticate to the LDAP server Certificate module authenticates to the LDAP server in order to search for a matching certificate. The DN entered here \
represents the account used for said authentication and must have read/search access to the LDAP server.
a108=LDAP Server Authentication Password password for the authentication user
# unused
a109=LDAP Attribute for Profile ID
# unused any valid attribute in a user entry (CN, SN) that can be used as the user ID.
a110=Use SSL/TLS for LDAP Access certificate module will use SSL/TLS to access the LDAP server
a111=Certificate Field Used to Access User Profile certificate module needs to read a value from the client certificate that can be used to search the LDAP server for a \
matching certificate.
a1111=Other Certificate Field Used to Access User Profile field is only used if the <i>Certificate Field Used to Access User Profile</i> attribute is set to <i>other</i>. This \
field allows a custom certificate field to be used as the basis of the user search.
a1112=SubjectAltNameExt Value Type to Access User Profile the Subject Alternative Name Field in preference to one of the standard certificate fields. RFC822Name or UPN will cause this field to have have precedence over the <i>Certificate Field Used to Access \
User Profile</i> or <i>Other Certificate Field Used to Access User Profile</i> attribute.<br/><br/>\
<i>NB </i>The client certificate must contain the <i>Subject Alternate Name Extension</i> for this function to operate.
a500=Authentication Level authentication level associated with this module. authentication module has an authentication level that can be used to indicate the level of security \
associated with the module; 0 is the lowest (and the default).
a113=Trusted Remote Hosts list of IP addresses trusted to supply client certificates. SSL/TLS is being terminated at a load balancer or at the Distributed Authentication server then this option can be used \
to ensure that only specified <i>trusted</i> hosts (identified by IP address) are allowed to supply client certificates to the certificate \
module,<br/><br/>Valid values for this list are as follows:<ul><li>none</li><li>any</li><li>multiple IP addresses</li></ul><br/><br/>\
The default value of <i>none</i> disables this functionality
a115=HTTP Header Name for Client Certificate name of the HTTP request header containing the certificate, only used when <i>Trusted Remote Hosts</i> mode is enabled.
amAuthCert-eeh-debug-desc=Turn on debugging.
amAuthCert-ff-aliases-desc=Certificate User Aliases
amAuthCert-debug.log=Log Messages
emailAddrTag=email address
noCert=User certificate not found
jssSockFactoryFail=Failed to create LDAP connection with JSS
NoCallbackHandler=No callback handler available
wrongLDAPServer=LDAP server and port number are misconfigured.
wrongStartDN=LDAP Start Search DN misconfigured.
noLDAPAttr=No value provided for attribute name to search LDAP.
noCRLAttr=No value provided for attribute name to search CRL.
noOtherAttr=No value provided for other field to access user profile.
noURLCertAuth=URL certificate authentication not enabled.
choiceIssuerDN=issuer DN
choiceIssuerCN=issuer CN
choiceIssuer0=issuer O
choiceSerialNumber=serial number
choiceSubjectDN=subject DN
choiceSubjectCN=subject CN
choiceSubjectUID=subject UID
choiceSubject0=subject O
choiceEmail=email address