08-03-2023 04:44 AM
Hello,
We just deployed the FMC and I was tasked to try and configure it so that we can use it in conjunction with our token cards during the authentication process. I configured an HTTPS certificate that's been signed by my CA and uploaded that into the FMC and enabled "Client Certificates" in the GUI.
I have an external connection with an active directory domain configured under the "External Authentication" section of the FMC and have it enabled. I clicked and check marked the "Use for CaC authentication and authorization", however I'm a little confused on what I need to put into the "CAC Environment Variable" and "CAC User Name Template".
I know these two lines need to come from the actual card certificate information. Just wondering if anyone could give me a good example of what needs to be put into those two lines.
We would like to have it so that we could authenticate and then have it reach back to certain users associated with a network admin group.
After it's configured correctly will the authentication and authorization process be automated or do we still have to manually put in the password and username?
Any help is appreciated! I know that there are guides and other forums that relate to this, but perhaps someone out there can give me a little more information to solve this puzzle.
05-16-2025 01:21 PM
Give these two settings a try:
CAC Environment Variable - SSL_CLIENT_SAN_OTHER_msUPN_0
CAC User Name Template - (.+)@example.com
05-19-2025 05:59 AM
Why not use SAML?
05-20-2025 09:38 AM - edited 05-20-2025 09:43 AM
How is SAML configured on a FMC? --- Nevermind I see it...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide