Browse Source
- change tb-hints Info and Regex examples as tb-help-popup - fix locales for hint-pull/7935/head
4 changed files with 50 additions and 12 deletions
@ -0,0 +1,18 @@ |
|||
##### X509 Certificate Chain info |
|||
|
|||
X.509 certificates strategy is used to provision devices by client certificates in two-way TLS communication. |
|||
|
|||
<b>This strategy can:</b> |
|||
* check for pre-provisioned devices |
|||
* update X.509 device credentials |
|||
* create new devices |
|||
|
|||
<b>The user uploads</b> X.509 certificate to the device profile and sets a regular expression to fetch the device name from *Common Name (CN)*. |
|||
|
|||
<b>Client certificates must</b> be signed by X.509 certificate, pre-uploaded for this device profile to provision devices by the strategy. |
|||
|
|||
<b>The client must</b> establish a TLS connection using the entire chain of certificates (this chain must include device profile X.509 certificate on the last level). |
|||
|
|||
If a device already exists with outdated X.509 credentials, this strategy automatically updates it with the device certificate's credentials from the chain. |
|||
|
|||
<b>Important:</b> Uploaded certificates should be neither root nor intermediate certificates that are provided by a well-known *Certificate Authority (CA)*. |
|||
@ -0,0 +1,15 @@ |
|||
#### Examples of RegEx usage |
|||
|
|||
* **Pattern:** <code>.*</code> - matches any character (until line terminators) |
|||
<br>**CN sample:** <code>DeviceName\nAdditionalInfo</code> |
|||
<br>**Pattern matches:** <code>DeviceName</code> |
|||
|
|||
* **Pattern:** <code>^([^@]+)</code> - matches any string that starts with one or more characters that are not the <code>@</code> symbol (<code>@</code> could be replaced by any other symbol) |
|||
<br>**CN sample:** <code>DeviceName@AdditionalInfo</code> |
|||
<br>**Pattern matches:** <code>DeviceName</code> |
|||
|
|||
* **Pattern:** <code>[\w]*$</code> (equivalent to <code>[a-zA-Z0-9_]\*$</code>) - matches zero or more occurences of any word character (letter, digit or underscore) at the end of the string |
|||
<br>**CN sample:** <code>AdditionalInfo2110#DeviceName_01</code> |
|||
<br>**Pattern matches:** <code>DeviceName_01</code> |
|||
|
|||
**Note:** Client will get error response in case regex is failed to match. |
|||
Loading…
Reference in new issue