client-certificate-auth API Reference
client-certificate-auth API Reference / extractor / ExtractorOptions
Interface: ExtractorOptions
Defined in: extractor.js:154
Properties
certificateHeader?
optionalcertificateHeader?:string
Defined in: extractor.js:158
Custom header name. Trust boundary: the proxy must strip this header from external requests; any source that can set it is trusted to assert client identity.
certificateSource?
optionalcertificateSource?:"aws-alb"|"aws-alb-verify"|"azure-app-service"|"cloudflare"|"cloudflare-rfc9440"|"envoy"|"traefik"
Defined in: extractor.js:155
Preset configuration. Trust boundary: the proxy must strip the preset's header from external requests; any source that can set it is trusted to assert client identity.
chainHeader?
optionalchainHeader?:string
Defined in: extractor.js:161
Optional second header carrying the certificate chain alongside the leaf. Split on commas per RFC 9440, each item parsed with the same headerEncoding, results linked via issuerCertificate. Leaf and chain together may not exceed MAX_CHAIN_CERTS certificates; a longer chain header rejects the request. For non-RFC-9440 encodings the comma split may not match the encoding's list convention.
fallbackToSocket?
optionalfallbackToSocket?:boolean
Defined in: extractor.js:167
Try socket if header extraction fails
headerEncoding?
optionalheaderEncoding?:"url-pem"|"url-pem-aws"|"xfcc"|"base64-der"|"rfc9440"
Defined in: extractor.js:166
Header encoding
includeChain?
optionalincludeChain?:boolean
Defined in: extractor.js:168
Include issuerCertificate chain
verifyHeader?
optionalverifyHeader?:string
Defined in: extractor.js:169
Header name for upstream verification status. Pairs with verifyValue, and requires certificateSource or certificateHeader: verification applies to header-based extraction only.
verifyValue?
optionalverifyValue?:string
Defined in: extractor.js:172
Expected value for successful verification. Pairs with verifyHeader.