
Chapter 7. The ThinLinc Client
Smart card - certificate filter
A certificate filter is used to present only allowed certificates for authentication, certificates that
does not match any filter will be hidden from the user.
When no certificate filters are configured, all available certificates on the smart card will be
available for authentication and therefore the autoconnect feature will not work.
If the resulting filtered list of certificate evaluates only one certificate for authentication and the
autoconnect feature is enabled, it will be used for authentication.
When the login dialog is displayed and the key shortcut control-shift-F8 is pressed, the certificate
filtering functionality is bypassed and gives you access to all certificates available on the smart card
for authentication.
To add a new filter just press the add button as shown in dialog Figure 7-12 or select an available
filter item in the lsit and press edit to change the settings for specific filter. Either way, the certificate
filter settings dialog Figure 7-13 will be shown where you can modify the settings of the specific
filter.
Figure 7-13. Certificate filter settings
Name
Enter name of the filter that will be seen in the list of filters.
Issuer
The certificate issuer field consists of a comma separated list of attribute-value pairs that all
must be present in the certificate issuer field. Commonly the "common name" of the issuer is
used, e.g. "cn=My CA". It is also possible to allow any issuer that are part of the same
organisation, e.g. "o=My Company Ltd.". Any registered object identifier descriptor can be
used as an attribute name (see IANA (http://www.iana.org/assignments/ldap-parameters) for a
full list).
58
Comentarios a estos manuales