Recognises a verified client certificate as an identity, or refuses it.
A chain through no authority this process holds is issuedHere: false.
One through a held authority is accepted only from a realm Issuing CA in
IDENTITY_USE_CASES, with clientAuth, naming exactly one person or
application; a person is then resolved to whoever holds their subject
now. Memoised by leaf digest and held authorities.
Parameters
input: any
{ leaf, chain, verified }, from
revocation_status.fromSocket()
Returns any
{ issuedHere, accepted }, with realm, kind, username,
serialHex and authority when accepted, or error and why when not
Recognises a verified client certificate as an identity, or refuses it.
A chain through no authority this process holds is
issuedHere: false. One through a held authority is accepted only from a realm Issuing CA inIDENTITY_USE_CASES, with clientAuth, naming exactly one person or application; a person is then resolved to whoever holds their subject now. Memoised by leaf digest and held authorities.