Cisco 5505 Administration Guide - Page 80

Identifier, Description, Appendix A, Sample, AnyConnect Profile and XML Schema

Page 80 highlights

Configuring Profile Attributes Chapter 7 Configuring and Using AnyConnect Client Operating Modes and User Profiles Table 7-4 Criteria for Certificate Distinguished Name Mapping Identifier CN SN GN N I GENQ DNQ C L SP ST O OU T EA ISSUER-CN ISSUER-SN ISSUER-GN ISSUER-N ISSUER-I ISSUER-GENQ ISSUER-DNQ "SSUER-C ISSUER-L ISSUER-SP ISSUER-ST ISSUER-O ISSUER-OU ISSUER-T ISSUER-EA Description SubjectCommonName SubjectSurName SubjectGivenName SubjectUnstructName SubjectInitials SubjectGenQualifier SubjectDnQualifier SubjectCountry SubjectCity SubjectState SubjectState SubjectCompany SubjectDept SubjectTitle SubjectEmailAddr IssuerCommonName IssuerSurName IssuerGivenName IssuerUnstructName IssuerInitials IssuerGenQualifier IssuerDnQualifier IssuerCountry IssuerCity IssuerState IssuerState IssuerCompany IssuerDept IssuerTitle IssuerEmailAddr The profile can contain none or more matching criteria. A certificate must match all specified criteria to be considered a matching certificate. Distinguished Name matching offers additional match criteria, including the ability for the administrator to specify that a certificate must or must not have the specified string, as well as whether wild carding for the string should be allowed. See Appendix A, "Sample AnyConnect Profile and XML Schema," for an example. 7-14 Cisco AnyConnect VPN Client Administrator Guide OL-12950-012

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

7-14
Cisco AnyConnect VPN Client Administrator Guide
OL-12950-012
Chapter 7
Configuring and Using AnyConnect Client Operating Modes and User Profiles
Configuring Profile Attributes
The profile can contain none or more matching criteria. A certificate must match all specified criteria to
be considered a matching certificate.
Distinguished Name
matching offers additional match criteria,
including the ability for the administrator to specify that a certificate must or must not have the specified
string, as well as whether wild carding for the string should be allowed. See
Appendix A, “Sample
AnyConnect Profile and XML Schema,”
for an example.
Table 7-4
Criteria for Certificate Distinguished Name Mapping
Identifier
Description
CN
SubjectCommonName
SN
SubjectSurName
GN
SubjectGivenName
N
SubjectUnstructName
I
SubjectInitials
GENQ
SubjectGenQualifier
DNQ
SubjectDnQualifier
C
SubjectCountry
L
SubjectCity
SP
SubjectState
ST
SubjectState
O
SubjectCompany
OU
SubjectDept
T
SubjectTitle
EA
SubjectEmailAddr
ISSUER-CN
IssuerCommonName
ISSUER-SN
IssuerSurName
ISSUER-GN
IssuerGivenName
ISSUER-N
IssuerUnstructName
ISSUER-I
IssuerInitials
ISSUER-GENQ
IssuerGenQualifier
ISSUER-DNQ
IssuerDnQualifier
"SSUER-C
IssuerCountry
ISSUER-L
IssuerCity
ISSUER-SP
IssuerState
ISSUER-ST
IssuerState
ISSUER-O
IssuerCompany
ISSUER-OU
IssuerDept
ISSUER-T
IssuerTitle
ISSUER-EA
IssuerEmailAddr