Configures the User Principal Name (UPN) that is encoded in the Other Name field of the Subject Alternative Name (SAN) field to match against the LDAP field.
Note
The default is the
x509-cert-san-upnattribute.
Note
Use the no aaa authorization certificate map-ldap match-cert-field command to reset the matched certificate field.
For details about configuring user attributes for the X.509 certificates, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.
Note
This command is not currently used on the Intelligent Virtual Execution - Server compute node.
Syntax
aaa authorization certificate map-ldap match-cert-field x509-cert-san-upn
no aaa authorization certificate map-ldap match-cert-field
Parameters
None
Example
The following example shows how to configure the UPN field of the SAN field to match the LDAP field.
hostname (config) # aaa authorization certificate map-ldap match-cert-field x509-cert-san-upn
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9.1
Endpoint Security (HX): Release 2.5
Network Security: Release 7.9.1
Intelligent Virtual Execution - Server: Release 7.9.1
Email Security — Server: Release 7.9.0