User Authentication

Trustpoint supports multiple authentication methods for human users:

  • Password authentication, with optional one-time password (OTP) verification

  • Certificate-based authentication using TLS client certificates

If certificate authentication is enabled, users can use either an associated client certificate or the password-based login flow.

Password + OTP

Password authentication remains enabled by default.

Administrators can configure the global password policy under User Authentication → Password + OTP. The policy includes settings such as:

  • minimum password length

  • password reuse prevention

  • password expiry

  • similarity checks

  • common-password validation

  • numeric-password validation

  • optional OTP requirement

OTP

OTP can be required globally for password-based logins.

When OTP is enabled:

  1. The user enters their username and password.

  2. If no authenticator is configured yet, Trustpoint guides the user through enrollment using a QR code.

  3. The user verifies the login with a code from their authenticator application.

  4. Existing users can also use an unused recovery code.

OTP applies to the password login flow. Certificate-based authentication is handled separately.

Certificate-Based Authentication

Trustpoint can authenticate users with TLS client certificates.

Certificate authentication must first be configured and enabled by an administrator under:

Management → User Authentication → Certificate

Trustpoint creates a dedicated CA hierarchy for this purpose:

  • Management Root CA

  • Management Issuing CA

The Management Issuing CA signs the user authentication certificates.

User Certificates

After certificate authentication has been enabled, users can manage their certificates from their profile.

A user can:

  • create a new client certificate

  • download the generated credential as PKCS#12

  • enable or disable an existing certificate

  • delete a certificate

The private key is generated in memory during certificate creation and is delivered to the user with the PKCS#12 file. Trustpoint stores the issued certificate and its association with the user.

Generated client certificates are intended for TLS client authentication and are linked to the corresponding Trustpoint user.

Current Limitations

The current implementation uses a Trustpoint-managed Management CA for user authentication certificates.

An administrator can currently:

  • generate the Management CA hierarchy

  • replace it with a newly generated hierarchy

  • delete it

External Management CA

Using an externally managed CA as the Management CA is currently not supported.

This means that administrators cannot yet:

  • import an existing external Management Root CA or Issuing CA

  • configure an external enterprise PKI as the issuer for Trustpoint user authentication certificates

  • select an arbitrary existing Trustpoint CA as the Management CA

Certificate-based authentication therefore currently requires the dedicated Management CA hierarchy generated by Trustpoint.

Support for external Management CAs can be added in a future implementation.