瀏覽代碼

Add short description about default authentication method in authorization docs

Following the discussion in #21556, adding a short description of the
default user authentication mechanism (without requiring authentication
plugins)
Signed-off-by: Liron Levin <liron@twistlock.com>
Liron Levin 9 年之前
父節點
當前提交
b2f2f162ad
共有 1 個文件被更改,包括 5 次插入0 次删除
  1. 5 0
      docs/extend/plugins_authorization.md

+ 5 - 0
docs/extend/plugins_authorization.md

@@ -49,6 +49,11 @@ Each plugin must reside within directories described under the
 **Note**: the abbreviations `AuthZ` and `AuthN` mean authorization and authentication
 **Note**: the abbreviations `AuthZ` and `AuthN` mean authorization and authentication
 respectively.
 respectively.
 
 
+## Default user authorization mechanism
+
+If TLS is enabled in the [Docker daemon](https://docs.docker.com/engine/security/https/), the default user authorization flow extracts the user details from the certificate subject name.
+That is, the `User` field is set to the client certificate subject common name, and the `AuthenticationMethod` field is set to `TLS`.
+
 ## Basic architecture
 ## Basic architecture
 
 
 You are responsible for registering your plugin as part of the Docker daemon
 You are responsible for registering your plugin as part of the Docker daemon