aaa authorization certificate map-ldap match-cert-field x509-cert-san-upn-username

Prev Next

Configures the user name of the User Principal Name (UPN) field without the domain name in the certificate to match against the LDAP field.

Note

Use the no aaa authorization certificate map-ldap match-cert-field command to reset the matched certificate field to use the default x509-cert-san-upn attribute.

For details about configuring user attributes for the X.509 certificates, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

aaa authorization certificate map-ldap match-cert-field x509-cert-san-upn-username

no aaa authorization certificate map-ldap match-cert-field

Parameters

None

Example

The following example shows how to configure the user name of the UPN field without the domain name in the certificate to match the LDAP field.

hostname (config) # aaa authorization certificate map-ldap match-cert-field x509-cert-san-upn-username

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Network Security: Release 7.9.1

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0