show aaa authorization certificate

Prev Next

Shows the configuration settings for certificate authorization.

For details about configuring LDAP mappings for authorization, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

show aaa authorization certificate

Parameters

None

Example

The following example shows the configuration settings for certificate authorization:

hostname # show aaa authorization certificate
Certificate based authorization settings:
  LDAP enabled               : yes
  LDAP Match Attribute       : uid
  Certificate field to match : x509-cert-san-email-username
  LDAP Search Filter         : (!(cn=Test Cardholder))
  Username override          : no

Output fields

The following table describes the output fields for the show aaa authorization certificate command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

LDAP enabled

Whether the LDAP server is enabled or disabled to authorize users that are already authenticated using the X.509 certificate.

LDAP Match Attribute

LDAP attribute to match the certificate authorization field that was specified with the aaa authorization certificate map-ldap match-cert-field command.

Certificate field to match

Certificate field to match the LDAP field for authorization.

LDAP Search Filter

LDAP search filter that is defined for certificate authorization.

Username override

Whether the LDAP override of the username setting is enabled or disabled.

User role

Admin

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Network Security: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0