Configures which attribute holds an email address to match the configured certificate authorization field.
Note
Use the no aaa authorization certificate map-ldap match-ldap-attribute command to reset the attribute of the LDAP account to use the default
sAMAccountNameattribute.
For details about configuring LDAP authorization for certificate authentication, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.
Note
This command is not currently used on the Intelligent Virtual Execution - Server compute node.
Syntax
aaa authorization certificate map-ldap match-ldap-attribute mail
no aaa authorization certificate map-ldap match-ldap-attribute
Parameters
None
Example
The following example shows how to configure which attribute holds an email address to match the configured certificate authorization field.
hostname (config) # aaa authorization certificate map-ldap match-ldap-attribute mail
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9.1
Endpoint Security (HX): Release 2.5
Network Security: Release 7.9.1
Intelligent Virtual Execution - Server: Release 7.9.1
Email Security — Server: Release 7.9.0