Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 345

Table 221, Certificate Namespace

Page 345 highlights

Attribute Name Values "Adding and Modifying Authentication Methods" on page 111). Phase2PAC l None - No PAC was used instead of an inner method handshake in the EAP-FAST authentication method l UserAuthPAC - A user authentication PAC was used instead of the user authentication inner method handshake in the EAP-FAST authentication method l PosturePAC - A posture PAC was used instead of the posture credential handshake in the EAPFAST authentication method Posture l Capable - The client is capable of providing posture credentials l Collected - Posture credentials were collected from the client l Not-Capable - The client is not capable of providing posture credentials l Unknown - It is not known whether the client is capable of providing credentials Status l None - No authentication took place l User - The user was authenticated l Machine - The machine was authenticated l Failed - Authentication failed l AuthSource-Unreachable - The authentication source was unreachable MacAuth l NotApplicable - Not a MAC Auth request l Known Client - Client MAC address was found in an authentication source l Unknown Client - Client MAC address was not found in an authentication source Username The username as received from the client (after the strip user name rules are applied FullUsername The username as received from the client (before the strip user name rules are applied Source The name of the authentication source used to authenticate the user Authentication namespace appears in the following editing contexts: n Role mapping policies l Certificate Namespace - The certificate namespace can be used in role mapping policies to define roles based on attributes in the client certificate presented by the end host. Client certificates are presented in mutually authenticated 802.1X EAP methods (EAP-TLS, PEAP/TLS, EAP-FAST/TLS). The attribute names and possible values with descriptions are shown in the table below: Table 221: Certificate Namespace Attributes Attribute Name Values Version Certificate version Serial-Number Certificate serial number Subject-DN, Subject-DC, Subject-UID, Subject-CN, Subject-GN, Subject-SN, Subject-C, Subject-L, Subject-ST, Subject-O, Subject-OU, Subject-emailAddress Attributes associated with the subject (user or machine, in this case). Not all of these fields are populated in a certificate. Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 345

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

Attribute
Name
Values
"Adding and Modifying Authentication Methods" on page 111
).
Phase2PAC
l
None
- No PAC was used instead of an inner method handshake in the EAP-FAST authentication
method
l
UserAuthPAC
- A user authentication PAC was used instead of the user authentication inner
method handshake in the EAP-FAST authentication method
l
PosturePAC
- A posture PAC was used instead of the posture credential handshake in the EAP-
FAST authentication method
Posture
l
Capable
- The client is capable of providing posture credentials
l
Collected
- Posture credentials were collected from the client
l
Not-Capable
- The client is not capable of providing posture credentials
l
Unknown
- It is not known whether the client is capable of providing credentials
Status
l
None
- No authentication took place
l
User
- The user was authenticated
l
Machine
- The machine was authenticated
l
Failed
- Authentication failed
l
AuthSource-Unreachable
- The authentication source was unreachable
MacAuth
l
NotApplicable
- Not a MAC Auth request
l
Known Client
- Client MAC address was found in an authentication source
l
Unknown Client
- Client MAC address was not found in an authentication source
Username
The username as received from the client (after the strip user name rules are applied
Full-
Username
The username as received from the client (before the strip user name rules are applied
Source
The name of the authentication source used to authenticate the user
Authentication namespace appears in the following editing contexts:
n
Role mapping policies
l
Certificate Namespace
- The certificate namespace can be used in role mapping policies to define roles based on
attributes in the client certificate presented by the end host. Client certificates are presented in mutually
authenticated 802.1X EAP methods (EAP-TLS, PEAP/TLS, EAP-FAST/TLS). The attribute names and possible
values with descriptions are shown in the table below:
Table 221:
Certificate Namespace Attributes
Attribute Name
Values
Version
Certificate version
Serial-Number
Certificate serial number
Subject-DN, Subject-DC, Subject-UID, Subject-CN, Subject-GN,
Subject-SN, Subject-C, Subject-L, Subject-ST, Subject-O,
Subject-OU, Subject-emailAddress
Attributes associated with the subject (user or
machine, in this case). Not all of these fields
are populated in a certificate.
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
345