---
title: CertificateUserExtractorNode
description: Resource path:
component: pingam
version: 8.1
page_id: pingam:entity-reference:sec-amster-entity-certificateuserextractornode
canonical_url: https://docs.pingidentity.com/pingam/8.1/entity-reference/sec-amster-entity-certificateuserextractornode.html
section_ids:
  sec-amster-entity-certificateuserextractornode-realm-ops: Realm Operations
  sec-amster-entity-certificateuserextractornode-realm-ops-create: create
  sec-amster-entity-certificateuserextractornode-realm-ops-delete: delete
  sec-amster-entity-certificateuserextractornode-realm-ops-gettype: getType
  sec-amster-entity-certificateuserextractornode-realm-ops-getupgradedconfig: getUpgradedConfig
  sec-amster-entity-certificateuserextractornode-realm-ops-query: query
  sec-amster-entity-certificateuserextractornode-realm-ops-read: read
  sec-amster-entity-certificateuserextractornode-realm-ops-update: update
  sec-amster-entity-certificateuserextractornode-realm-ops-versioninfo: versionInfo
---

# CertificateUserExtractorNode

## Realm Operations

Resource path:

```
/realm-config/authentication/authenticationtrees/nodes/product-CertificateUserExtractorNode/1.0
```

Resource version: `3.0`

### create

**Usage**

```
am> create CertificateUserExtractorNode --realm Realm --id id --body body
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

* *\--body*

  The resource in JSON format, described by the following JSON schema:

  ```json
  {
    "type" : "object",
    "properties" : {
      "otherCertificateAttributeToProfileMapping" : {
        "title" : "Other Certificate Field Used to Access User Profile",
        "description" : "This field is only used if the <em>Certificate Field Used to Access User Profile</em> attribute is set to <em>other</em>. This field allows a custom certificate field to be used as the basis of the user search.",
        "propertyOrder" : 200,
        "type" : "string",
        "exampleValue" : ""
      },
      "certificateAttributeProfileMappingExtension" : {
        "title" : "SubjectAltNameExt Value Type to Access User Profile",
        "description" : "Use the Subject Alternative Name Field in preference to one of the standard certificate fields.<br><br>Selecting RFC822Name or UPN will cause this field to have have precedence over the <em>Certificate Field Used to Access User Profile</em> or <em>Other Certificate Field Used to Access User Profile</em> attribute.",
        "propertyOrder" : 300,
        "type" : "string",
        "exampleValue" : ""
      },
      "certificateAttributeToProfileMapping" : {
        "title" : "Certificate Field Used to Access User Profile",
        "description" : "The certificate node needs to read a value from the client certificate that can be used to search the LDAP server for the user. This value from the certificate will be populated in shared state under the username key.",
        "propertyOrder" : 100,
        "type" : "string",
        "exampleValue" : ""
      }
    },
    "required" : [ "certificateAttributeProfileMappingExtension", "certificateAttributeToProfileMapping" ]
  }
  ```

### delete

**Usage**

```
am> delete CertificateUserExtractorNode --realm Realm --id id
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

### getType

List information related to the node such as a name, description, tags and metadata.

**Usage**

```
am> action CertificateUserExtractorNode --realm Realm --actionName getType
```

### getUpgradedConfig

Get the upgraded configuration for the node type.

**Usage**

```
am> action CertificateUserExtractorNode --realm Realm --body body --actionName getUpgradedConfig --targetVersion targetVersion
```

**Parameters**

* *\--body*

  The resource in JSON format, described by the following JSON schema:

  ```json
  {
    "type" : "object",
    "title" : "The current configuration of the node type."
  }
  ```

* *\--targetVersion*

  \=== listOutcomes

List the available outcomes for the node type.

**Usage**

```
am> action CertificateUserExtractorNode --realm Realm --body body --actionName listOutcomes
```

**Parameters**

* *\--body*

  The resource in JSON format, described by the following JSON schema:

  ```json
  {
    "description" : "Some configuration of the node. This does not need to be complete against the configuration schema.",
    "type" : "object",
    "title" : "Node configuration"
  }
  ```

### query

Get the full list of instances of this collection. This query only supports `_queryFilter=true` filter.

**Usage**

```
am> query CertificateUserExtractorNode --realm Realm --filter filter
```

**Parameters**

* *\--filter*

  A CREST formatted query filter, where "true" will query all.

### read

**Usage**

```
am> read CertificateUserExtractorNode --realm Realm --id id
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

### update

**Usage**

```
am> update CertificateUserExtractorNode --realm Realm --id id --body body
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

* *\--body*

  The resource in JSON format, described by the following JSON schema:

  ```json
  {
    "type" : "object",
    "properties" : {
      "otherCertificateAttributeToProfileMapping" : {
        "title" : "Other Certificate Field Used to Access User Profile",
        "description" : "This field is only used if the <em>Certificate Field Used to Access User Profile</em> attribute is set to <em>other</em>. This field allows a custom certificate field to be used as the basis of the user search.",
        "propertyOrder" : 200,
        "type" : "string",
        "exampleValue" : ""
      },
      "certificateAttributeProfileMappingExtension" : {
        "title" : "SubjectAltNameExt Value Type to Access User Profile",
        "description" : "Use the Subject Alternative Name Field in preference to one of the standard certificate fields.<br><br>Selecting RFC822Name or UPN will cause this field to have have precedence over the <em>Certificate Field Used to Access User Profile</em> or <em>Other Certificate Field Used to Access User Profile</em> attribute.",
        "propertyOrder" : 300,
        "type" : "string",
        "exampleValue" : ""
      },
      "certificateAttributeToProfileMapping" : {
        "title" : "Certificate Field Used to Access User Profile",
        "description" : "The certificate node needs to read a value from the client certificate that can be used to search the LDAP server for the user. This value from the certificate will be populated in shared state under the username key.",
        "propertyOrder" : 100,
        "type" : "string",
        "exampleValue" : ""
      }
    },
    "required" : [ "certificateAttributeProfileMappingExtension", "certificateAttributeToProfileMapping" ]
  }
  ```

### versionInfo

List the versions available for the node type.

**Usage**

```
am> action CertificateUserExtractorNode --realm Realm --actionName versionInfo
```
