Skip to content

client-certificate-auth API Reference


client-certificate-auth API Reference / helpers / allowCA

Function: allowCA() ​

allowCA(caCertificates, options?): ValidationCallback

Defined in: helpers.js:715

Create a validation callback that accepts certificates issued by one of the given CA certificates, directly or through the issuerCertificate chain attached with includeChain: true.

It performs the subset of PKIX path validation that applies to a forwarded client certificate: issuer name and signature at every link, keyUsage keyCertSign where an issuer carries the extension, basicConstraints cA on every CA including the anchor, pathLenConstraint counting non-self-issued intermediates, clientAuth in the Extended Key Usage of every certificate on the path that carries one, digitalSignature or keyAgreement in the leaf's keyUsage when present, validity windows on every certificate, and rejection of any certificate carrying name constraints at any criticality or any other critical extension it does not process, so a name-constrained or policy-constrained intermediate anywhere in the chain fails the check. It does not process name constraints or certificate policies, and does not check revocation. Where the proxy can validate the client certificate itself, prefer that.

This establishes trust for passthrough presets (aws-alb, azure-app-service), where the proxy forwards the presented certificate without validating it. Anchors must be CA certificates that permit clientAuth; intermediates may be listed alongside roots to trust them directly, and a specific leaf is pinned with allowFingerprints instead. Throws at construction if a CA certificate cannot be parsed, is not a CA, does not permit clientAuth, carries name constraints or an unsupported critical extension, or sits in a PEM bundle whose blocks cannot all be read, and if maxDepth is not a positive integer.

Parameters ​

caCertificates ​

string | Buffer<ArrayBufferLike> | (string | Buffer<ArrayBufferLike>)[]

PEM or DER encoded CA certificates; a PEM bundle contributes every certificate it holds

options? ​

maxDepth bounds the number of certificates walked, leaf included (default 10)

maxDepth? ​

number

Returns ​

ValidationCallback

Example ​

ts
app.use(clientCertificateAuth(allowCA(readFileSync('ca.pem')), {
  certificateSource: 'aws-alb',
  includeChain: true
}));

Released under the MIT License.