<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE - Identity resolution failed - ERROR_NO_SUCH_USER in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/4520523#M571784</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;We have:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;- ISE&amp;nbsp;&lt;SPAN&gt;3.0.0.458&lt;/SPAN&gt;&lt;BR /&gt;- AnyConnect&lt;BR /&gt;- ASA&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Users connect with AnyConnect to the corporate network using a certificate. On ASA - We take the attribute CN from it (username-from-certificate CN).&lt;/P&gt;&lt;P&gt;Example: CN - Ivan Ivanov.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During authentication, ISE starts looking for a user in AD, but we get an error: Identity resolution failed - ERROR_NO_SUCH_USER.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;24325&amp;nbsp;Resolving identity - Ivan Ivanov&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;24313&amp;nbsp;Search for matching accounts at join point - test.ru&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;24318&amp;nbsp;No matching account found in forest -&amp;nbsp;test.ru&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;24322 I&lt;SPAN&gt;dentity resolution detected no matching account&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;24352&amp;nbsp;Identity resolution failed - ERROR_NO_SUCH_USER&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you look for the user Ivan.ivanov (sAMAccountName) when adding attributes, then everything is fine. But if we search for the user Ivan Ivanov, we will get the error above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please tell me how we can solve this problem? After all, we cannot substitute the sAMAccountName attribute on the ASA (username-from-certificate).&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sAMAccountName&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The error is repeated for any parameters in Certificate Authentication Profile.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Dec 2021 12:46:16 GMT</pubDate>
    <dc:creator>Alina S</dc:creator>
    <dc:date>2021-12-17T12:46:16Z</dc:date>
    <item>
      <title>Cisco ISE - Identity resolution failed - ERROR_NO_SUCH_USER</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/4520523#M571784</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;We have:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;- ISE&amp;nbsp;&lt;SPAN&gt;3.0.0.458&lt;/SPAN&gt;&lt;BR /&gt;- AnyConnect&lt;BR /&gt;- ASA&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Users connect with AnyConnect to the corporate network using a certificate. On ASA - We take the attribute CN from it (username-from-certificate CN).&lt;/P&gt;&lt;P&gt;Example: CN - Ivan Ivanov.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During authentication, ISE starts looking for a user in AD, but we get an error: Identity resolution failed - ERROR_NO_SUCH_USER.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;24325&amp;nbsp;Resolving identity - Ivan Ivanov&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;24313&amp;nbsp;Search for matching accounts at join point - test.ru&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;24318&amp;nbsp;No matching account found in forest -&amp;nbsp;test.ru&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;24322 I&lt;SPAN&gt;dentity resolution detected no matching account&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;24352&amp;nbsp;Identity resolution failed - ERROR_NO_SUCH_USER&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you look for the user Ivan.ivanov (sAMAccountName) when adding attributes, then everything is fine. But if we search for the user Ivan Ivanov, we will get the error above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please tell me how we can solve this problem? After all, we cannot substitute the sAMAccountName attribute on the ASA (username-from-certificate).&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sAMAccountName&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The error is repeated for any parameters in Certificate Authentication Profile.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 12:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/4520523#M571784</guid>
      <dc:creator>Alina S</dc:creator>
      <dc:date>2021-12-17T12:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Identity resolution failed - ERROR_NO_SUCH_USER</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/4520771#M571795</link>
      <description>&lt;P&gt;It looks to me as if the certificate does not contain a UPN (user principal name) - like Ivan.Ivanov&amp;nbsp; or &lt;A href="mailto:Ivan.Ivanov@somedomain" target="_blank"&gt;Ivan.Ivanov@somedomain&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Have a look at the certificate (Subject and Subject Alternative Name) - you need to put something in there that ISE can use to lookup in AD. It won't work with the "Full Name" like Ivan Ivanov. By default, this is what Windows CA would put in the Subject CN. It's nice and human-readable, but not machine-readable.&lt;/P&gt;
&lt;P&gt;One solution would be to change the cert template to add the UPN into the SAN. Re-issue the cert and test again.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 20:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/4520771#M571795</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-12-17T20:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Identity resolution failed - ERROR_NO_SUCH_USER</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/4520942#M571803</link>
      <description>&lt;P&gt;We have UPN - &lt;A href="mailto:Ivan.ivanov@test.ru" target="_blank" rel="noopener"&gt;Ivan.ivanov@test.ru&lt;/A&gt;, but with such settings on the ASA (username-from-certificate UPN) the ISE shows an error: 24325 Resolving Identity - &amp;lt;Unknown&amp;gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issuing new certificates is quite problematic, since there are many existing users &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; But just in case, I'll ask right away.&lt;BR /&gt;If we use SAN, what attribute to specify in the command:&amp;nbsp;username-from-certificate &amp;lt;?&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Dec 2021 10:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/4520942#M571803</guid>
      <dc:creator>Alina S</dc:creator>
      <dc:date>2021-12-18T10:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Identity resolution failed - ERROR_NO_SUCH_USER</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/5013295#M587099</link>
      <description>&lt;P&gt;Do you have multiple domains or forest trust to other domains on this AD join point? If so, did you the correct domain for authentication ?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 00:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-identity-resolution-failed-error-no-such-user/m-p/5013295#M587099</guid>
      <dc:creator>Sri Harsha Dasari</dc:creator>
      <dc:date>2024-02-06T00:10:19Z</dc:date>
    </item>
  </channel>
</rss>

