aaa authorization certificate map-ldap match-ldap-attribute sAMAccountName

Prev Next

Configures which attribute holds the login name to match the configured certificate authorization field.

Note

The default is the sAMAccountName attribute.

Note

Use the no aaa authorization certificate map-ldap match-ldap-attribute command to reset the attribute of the LDAP account.

For details about configuring LDAP authorization for certificate authentication, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

aaa authorization certificate map-ldap match-ldap-attribute sAMAccountName

no aaa authorization certificate map-ldap match-ldap-attribute

Parameters

None

Example

The following example shows how to configure which attribute holds the login name to match the configured certificate authorization field.

hostname (config) # aaa authorization certificate map-ldap match-ldap-attribute sAMAccountName

User role

Admin

Command mode

Configuration

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Network Security: Release 7.9.1

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0