X509 Settings

Disable or enable X509 (client certificate / smartcard) as an MFA on this instance.

Note

Selecting this item always continues straight into the mTLS Settings configuration flow afterwards (CA chain, CRL, verify depth), regardless of whether you enabled or disabled X.509 here. This is intentional β€” X.509 as MFA cannot work without a trusted CA installed β€” but it means you cannot use this menu item purely to flip the toggle without also being asked about mTLS configuration.

Status on Login Settings

Login           ENABLED
YubiOTP         ENABLED
TOTP            ENABLED
X509 Smartcard  ENABLED
Smart-ID        DISABLED
BankID          DISABLED
DUO             DISABLED

Disable X509 as MFA? (y/<N>): y

Login           ENABLED
YubiOTP         ENABLED
TOTP            ENABLED
X509 Smartcard  DISABLED
Smart-ID        DISABLED
BankID          DISABLED
DUO             DISABLED

(Press any key to continue)

If X509 already is disabled, another screen is shown and it’s possible to enable X509 again.

Status on Login Settings

Login           ENABLED
YubiOTP         ENABLED
TOTP            ENABLED
X509 Smartcard  DISABLED
Smart-ID        DISABLED
BankID          DISABLED
DUO             DISABLED

Enable X509 as MFA? (<Y>/n): y

Login           ENABLED
YubiOTP         ENABLED
TOTP            ENABLED
X509 Smartcard  ENABLED
Smart-ID        DISABLED
BankID          DISABLED
DUO             DISABLED

(Press any key to continue)