10-18-2017 03:37 PM - edited 03-12-2019 04:38 AM
Hello
Cant seem to remember what configuration allows you to validate the certificate based on a certain field.
ideally, I am looking authenticate a group of users who will have a certificate with an attribute setup. Is it possible to build a configuration in the ASA that can match a custom field in the certificate? Users that had certificates from the same PKI but didn't have the correct certificate template with the field setup would be denied to the VPN.
I think I remember a configuration in IOS that allowed you specify an attribute to be checked when validating the certificate. E.g. check the subject name contains a value when performing the validation.
Thanks
10-18-2017 03:54 PM
Hello @is.infrastructure1,
The feature is called "certificate mapping" and here are some links to make the configuration based on whatever requirement you want to check on the certificate:
HTH
Gio
10-19-2017 06:59 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide