Use the menu options in this section to configure the user attributes for certificate authentication.
To configure the user attributes for certificate authentication:
Log in to the NDR as npadmin using the NDR IP address or FQDN. For example:
$ ssh npadmin@10.1.0.1or
$ ssh npadmin@exampleFQDNEnter privileged mode:
npadmin@ia> enableEnter the npadmin password. The password can be 5 to 24 characters long.
[sudo] password for npadmin: <password>Enter configuration mode:
npadmin@ia# configure systemEnter configuration CAC menu.
npadmin@ia(config)# authenticationIn the CAC/PIV configuration menu, select
1to access the Authentication Mechanism menu.Select
2to select LDAP.Select
Qto save your changes and exit to the configure system menu.Enter the CAC/PIV configuration menu.
npadmin@ia(config)# authenticationSelect
2to configure LDAP.Make configuration changes to one of the following user attributes. Press
Qto save your changes and exit the LDAP configuration menu.x509-cert-subject—Specifies the name in the subject field in the certificate.x509-cert-subject-cn—Specifies the Common Name (CN) from the DN attribute in the certificate.x509-cert-san-email—Specifies an email address in the Subject Alternative Name (SAN) field of the certificate. You are allowed to have multiple subfields for SAN.x509-cert-san-email-username—Specifies the user name of the email address without the domain name in the certificate.x509-cert-san-upn—Specifies the User Principal Name (UPN) that is encoded in the "Other Name" field of the SAN field in the certificate.