Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 346

Tips Namespace, Endpoint Namespace, Device Namespace, LocalUser Namespace, CheckType, UniqueID

Page 346 highlights

Attribute Name Values Issuer-DN, Issuer-DC, Issuer-UID, Issuer-CN, Issuer-GN, IssuerSN, Issuer-C, Issuer-L, Issuer-ST, Issuer-O, Issuer-OU, IssueremailAddress Attributes associated with the issuer (Certificate Authorities or the enterprise CA). Not all of these fields are populated in a certificate. Subject-AltName-Email, Subject-AltName-DNS, SubjectAltName-URI, Subject-AltName-DirName, Subject-AltNameIPAddress, Subject-AltName-RegisterdID, Subject-AltNamemsUPN Attributes associated with the subject (user or machine, in this case) alternate name. Not all of these fields are populated in a certificate. Certificate namespace appears in the following editing contexts: n Role mapping policies l Tips Namespace - Tips namespace has two pre-defined attributes: Role and Posture. Values are assigned to these attributes at run-time after Policy Manager evaluates role mapping and posture related policies. The value for the Role attribute is a set of roles assigned by the either the role mapping policy or the post-audit policy. The value value of the Role attribute can also be a dynamically fetched "Enable as role" attribute from the authorization source. The value for the Posture attribute is one of HEALTHY, CHECKUP, TRANSITION, QUARANTINE, INFECTED or UNKNOWN. The posture value is computed after Policy Manager evaluates internal posture policies, gets posture status from posture servers or audit servers. Tips namespace appears in the following editing contexts: n Enforcement policies l Host Namespace - Host namespace has a number of pre-defined attributes: Name, OSType, FQDN, UserAgent, CheckType, UniqueID, AgentType and InstalledSHAs. Host:Name, Host:OSType, Host:FQDN, Host:AgentType, Host:InstalledSHAs are only populated when request is originated by a Microsot NAP-compatible agent. UserAgent and CheckType are present when Policy Manager acts as a Web authentication portal. l Endpoint Namespace - Endpoint namespace has the following attributes: Disabled By, Disabled Reason, Enabled By, Enabled Reason, Info URL. Use these attributes look for attributes of authenticating endpoints (present in the Policy Manager endpoints list). l Device Namespace - Device namespace has the attributes associated with the network device that originated the request. Device namespace has four pre-defined attributes: Location, OS-Version, Device-Type and DeviceVendor. Custom attributes also appear in the attribute list if they are defined as custom tags for the device. Note that these attribtues can be used only if you have pre-populated the values for these attributes when a network device is configured in Policy Manager. l LocalUser Namespace - LocalUser namespace has the attributes associated with the local user (resident in the Policy Manager local user database) who authenticated in this session. As the name suggests, this namespace is only applicable if a local user authenticated. LocalUser namespace has four pre-defined attributes: Phone, Email, Sponsor and Designation. Custom attributes also appear in the attribute list if they are defined as custom tags for the local user. Note that these attribtues can be used only if you have pre-populated the values for these attributes when a local user is configured in Policy Manager. l GuestUser Namespace - GuestUser namespace has the attributes associated with the guest user (resident in the Policy Manager guest user database) who authenticated in this session. As the name suggests, this namespace is only applicable if a guest user authenticated. GuestUser namespace has six pre-defined attributes: CompanyName, Location, Phone, Email, Sponsor and Designation. Custom attributes also appear in the attribute list if they are defined as custom tags for the guest user. Note that these attribtues can be used only if you have prepopulated the values for these attributes when a guest user is configured in Policy Manager. 346 Dell Networking W-ClearPass Policy Manager 6.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

346
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
Attribute Name
Values
Issuer-DN, Issuer-DC, Issuer-UID, Issuer-CN, Issuer-GN, Issuer-
SN, Issuer-C, Issuer-L, Issuer-ST, Issuer-O, Issuer-OU, Issuer-
emailAddress
Attributes associated with the issuer
(Certificate Authorities or the enterprise CA).
Not all of these fields are populated in a
certificate.
Subject-AltName-Email, Subject-AltName-DNS, Subject-
AltName-URI, Subject-AltName-DirName, Subject-AltName-
IPAddress, Subject-AltName-RegisterdID, Subject-AltName-
msUPN
Attributes associated with the subject (user or
machine, in this case) alternate name. Not all
of these fields are populated in a certificate.
Certificate namespace appears in the following editing contexts:
n
Role mapping policies
l
Tips Namespace
- Tips namespace has two pre-defined attributes: Role and Posture. Values are assigned to these
attributes at run-time after Policy Manager evaluates role mapping and posture related policies. The value for the
Role attribute is a set of roles assigned by the either the role mapping policy or the post-audit policy. The value
value of the Role attribute can also be a dynamically fetched “Enable as role” attribute from the authorization
source. The value for the Posture attribute is one of HEALTHY, CHECKUP, TRANSITION, QUARANTINE,
INFECTED or UNKNOWN. The posture value is computed after Policy Manager evaluates internal posture
policies, gets posture status from posture servers or audit servers.
Tips namespace appears in the following editing contexts:
n
Enforcement policies
l
Host Namespace
- Host namespace has a number of pre-defined attributes: Name, OSType, FQDN, UserAgent,
CheckType, UniqueID, AgentType and InstalledSHAs. Host:Name, Host:OSType, Host:FQDN, Host:AgentType,
Host:InstalledSHAs are only populated when request is originated by a Microsot NAP-compatible agent.
UserAgent and CheckType are present when Policy Manager acts as a Web authentication portal.
l
Endpoint Namespace
- Endpoint namespace has the following attributes: Disabled By, Disabled Reason, Enabled
By, Enabled Reason, Info URL. Use these attributes look for attributes of authenticating endpoints (present in
the Policy Manager endpoints list).
l
Device Namespace
- Device namespace has the attributes associated with the network device that originated the
request. Device namespace has four pre-defined attributes: Location, OS-Version, Device-Type and Device-
Vendor. Custom attributes also appear in the attribute list if they are defined as custom tags for the device. Note
that these attribtues can be used only if you have pre-populated the values for these attributes when a network
device is configured in Policy Manager.
l
LocalUser Namespace
- LocalUser namespace has the attributes associated with the local user (resident in the
Policy Manager local user database) who authenticated in this session. As the name suggests, this namespace is
only applicable if a local user authenticated. LocalUser namespace has four pre-defined attributes: Phone, Email,
Sponsor and Designation. Custom attributes also appear in the attribute list if they are defined as custom tags
for the local user. Note that these attribtues can be used only if you have pre-populated the values for these
attributes when a local user is configured in Policy Manager.
l
GuestUser Namespace
- GuestUser namespace has the attributes associated with the guest user (resident in the
Policy Manager guest user database) who authenticated in this session. As the name suggests, this namespace is
only applicable if a guest user authenticated. GuestUser namespace has six pre-defined attributes: Company-
Name, Location, Phone, Email, Sponsor and Designation. Custom attributes also appear in the attribute list if
they are defined as custom tags for the guest user. Note that these attribtues can be used only if you have pre-
populated the values for these attributes when a guest user is configured in Policy Manager.