X509は発行者dnのみで認証できないか

I want to log in with X509 only with the issuer DN without linking it to the user ID. This is because we want anyone to be able to log in with a client certificate issued by a certain company issued by a CA after identifying the user by ID/password authentication. I’m in so much trouble, please help me…