# How to use a client certificate at the invites page

**URL:** <https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894>\
**Category:** Support\
**Created:** [18 februari 2020 om 13:29 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894 "2020-02-18T13:29:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![harmstra](https://avatars.discourse-cdn.com/v4/letter/h/3da27b/32.png) [@harmstra](https://meta.discourse.org/u/harmstra)\
**Post date:** [18 februari 2020 om 13:29 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894/1 "2020-02-18T13:29:27Z")

</div>

Hi,

We have an ‘invite only’ Discourse installation. When we send an invite, the invitee should only be able to accept the invitation when a certain client certificatie is present in the browser.

Any clues on how to achieve this?

Grtz Harmstra

---

<div class="post-metadata">

**Author:** ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)\
**Post date:** [19 februari 2020 om 06:05 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894/2 "2020-02-19T06:05:25Z")

</div>

You need something like this to end up in your nginx configuration:

```plaintext
ssl_client_certificate /path/to/ca.pem;
ssl_verify_client on;

```

If it should just be present for invites, you will need to do this in a `location` block containing the invitation accept route.

---

<div class="post-metadata">

**Author:** ![anned20](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/anned20/32/170385_2.png) [@anned20](https://meta.discourse.org/u/anned20)\
**Post date:** [19 februari 2020 om 14:25 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894/3 "2020-02-19T14:25:10Z")

</div>

Hi @michaeld,

Is it also possible to use a certificate field and save it to the user instance as a user field? So let’s say that we want to save the expiry date, can we do that?

---

<div class="post-metadata">

**Author:** ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)\
**Post date:** [19 februari 2020 om 15:03 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894/4 "2020-02-19T15:03:07Z")

</div>

This seems bizarrely complicated. What is your use case?

---

<div class="post-metadata">

**Author:** ![anned20](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/anned20/32/170385_2.png) [@anned20](https://meta.discourse.org/u/anned20)\
**Post date:** [19 februari 2020 om 15:27 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894/5 "2020-02-19T15:27:18Z")

</div>

I agree that it is.

The use case is that there’s an organization here that does authentication of companies using those client certificates. We’re trying to create a Discourse instance where only those companies get access to it. Seems easy enough based on the nginx snippet provided by @michaeld.

In that certificate is also a company number, we’d like to get that number and make it available in the Discourse instance. That way the can easily find each other and they’re identifiable based on just their company number.

I hope it’s clear by now, if not, feel free to ask

---

<div class="post-metadata">

**Author:** ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)\
**Post date:** [19 februari 2020 om 15:56 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894/6 "2020-02-19T15:56:25Z")

</div>

Wow. That sounds less silly than I’d have imagined!

> [@anned20](#):
>
> That way the can easily find each other and they’re identifiable based on just their company number.

Can you count on people from those companies to be using a company email address? That’d be much easier than a plugin that could read the certificate. You could even map it backward to the company number if that number is somehow very important.

---

<div class="post-metadata">

**Author:** ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)\
**Post date:** [19 februari 2020 om 18:51 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894/7 "2020-02-19T18:51:22Z")

</div>

You could pass the certificate to Discourse using a line like

```plaintext
proxy_set_header X-Cert-DN: $ssl_client_s_dn;

```

and then have some sort of plugin to read the value from the header.

---

<div class="post-metadata">

**Author:** ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)\
**Post date:** [21 januari 2024 om 23:23 UTC](https://meta.discourse.org/t/how-to-use-a-client-certificate-at-the-invites-page/141894/8 "2024-01-21T23:23:35Z")

</div>


