Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,297,144
Community Members
 
Community Events
165
Community Groups

Adding a user with CAC credentials using the REST API

Edited

All of the examples I've been able find on the internet involve Crowd user accounts with a PASSWORD. I want to add users with CAC Credentials.

2 answers

1 accepted

1 vote
Answer accepted

Hi,

I believe that your only option is a password. Can you confirm what you mean by CAC credentials though?

CCM

Common Access Card, the DoD's PIV card variant. A badge card which stores X.509 SSL certificates and some profile properties. PIV cards, including CACs, are supported by the leading Operating Systems and Web Browsers. When a server and a client enter into an SSL handshake such that the client as well as the server must provide SSL certificates, the browser or a card-capable application will ask the user to insert the CAC (or the PIV), to enter a PIN, and to choose one of several X.509 certs to send into the SSL handshake protocol. The server can use the client's cert to retrieve profile fields that can be handed to an Identity Provider (such as MS AD, Ping Federate, etc) to retrieve any known identity for that client cert. With the SSL session established, the server knows that the client has the right pass phrase (their PIN) and the secondary factor (the card with the crypto certs) and the IdP verifies that the cert indicates a particular user - so the app-server can grant authentication to the incoming request.

To support CAC access over the API calls, it is the Jira server that needs to come to demand Mutual TLS for incoming API requests and to pair with an IdP to look up users from the arriving certs (versus looking for either Basic Auth or Bearer Auth HTTP Headers)

It's not something that a client of the API can implement on its own.

You are correct, the only option is a password. However, since I have posted this, I learned that my organization already has a process in place to handle it. Users are created with a psuedo random password, and then the CAC credentials are added via SQL as a second step.

Company policy prevents me from posting the exact code here, but I think I can safely say that we add a new entry in cwd_user_attribute with attribute_name = 'commonName' and attribute_lower_value = CAC credentials.

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Posted in Jira Service Management

Jira Service Management Documentation Opportunities

Hello everyone, Hope everyone is safe! A few months ago we posted an article sharing all the new articles and documentation that we, the AMER Jira Service Management team created. As mentioned ...

338 views 0 10
Join discussion

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you