Shows the configuration settings for certificate authorization.
For details about configuring LDAP mappings for authorization, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.
Note
This command is not currently used on the Intelligent Virtual Execution - Server compute node.
Syntax
show aaa authorization certificate
Parameters
None
Example
The following example shows the configuration settings for certificate authorization:
hostname # show aaa authorization certificate Certificate based authorization settings: LDAP enabled : yes LDAP Match Attribute : uid Certificate field to match : x509-cert-san-email-username LDAP Search Filter : (!(cn=Test Cardholder)) Username override : no
Output fields
The following table describes the output fields for the show aaa authorization certificate command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
LDAP enabled | Whether the LDAP server is enabled or disabled to authorize users that are already authenticated using the X.509 certificate. |
LDAP Match Attribute | LDAP attribute to match the certificate authorization field that was specified with the |
Certificate field to match | Certificate field to match the LDAP field for authorization. |
LDAP Search Filter | LDAP search filter that is defined for certificate authorization. |
Username override | Whether the LDAP override of the username setting is enabled or disabled. |
User role
Admin
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9.1
Network Security: Release 7.9.1
Endpoint Security (HX): Release 2.5
Intelligent Virtual Execution - Server: Release 7.9.1
Email Security — Server: Release 7.9.0