You can use the Policy Server's certificate mapping feature to provide custom mappings for certificates.
Note: The following procedure assumes you are creating a new object. You can also copy the properties of an existing object to create an object. More information exists in Duplicate Policy Server Objects.
To create and use a custom attribute in a certificate mapping
The Create Certificate Mapping pane opens.
Certificate mapping settings open.
Note: Click Help for descriptions of settings and controls, including their respective requirements and limits.
The Mapping Expressions field opens.
This notation is used to specify two different attributes that are acceptable for a certificate mapping.
%{E/Email}
%{S/ST}
%{UID/UserID}
Note: More information about custom mapping expressions exists in Certificate Attributes that Require Custom Mappings.
The custom mapping is saved. The Policy Server now handles requests from both Web Servers and the Test tool where the Email attribute is represented differently in the issuer DN. You can use this process for any of the other attributes mentioned in Certificate Attributes that Require Custom Mappings.
Copyright © 2010 CA. All rights reserved. | Email CA about this topic |