aaa authorization certificate map-ldap search-filter

Prev Next

Defines an LDAP search filter for certificate authentication.

An administrator can define an LDAP search filter in the configuration that controls which user can log in using a certificate and then be authorized using LDAP.

Note

If the text of the <filter_string> parameter contains spaces, enclose the string with double quotation marks.

For details about configuring LDAP authorization for certificate authentication, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

[no] aaa authorization certificate map-ldap search-filter <filter_string>

Parameters

no

Use the no form of this command to remove the LDAP search filter for certificate authentication.

filter_string

LDAP search filter string for certificate authentication.

Example

The following example shows how to configure the LDAP search filter for certificate authorization.

hostname (config) # aaa authorization certificate map-ldap search-filter "(!(cn=Test Cardholder))"

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Network Security: Release 7.9.1

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0