Skip to main content

Modify user certificate settings

Use this procedure to configure policy settings for user certificate authentication.

Before you begin, review limitations and setup requirements in Manage user certificate authenticators.

Modify user certificate authenticator settings

  1. Click > Policies > Authenticators. The Authenticators page appears.

  2. Select User Certificate Authenticator. The User Certificate Authenticator page appears.

  3. Add User Matching Rules:

    1. Click Add. The Add Matching Rule dialog box appears.

    2. From Certificate Component, select the certificate component used to match the user.

    3. From the User Attributes drop-down list, select the user attribute that matches the Certificate Component.

    4. Supported system user attributes include user ID (including aliases), User Principal Name, and security ID. Custom user attributes are also supported.

    5. Repeat these steps to add more User Matching Rules.

      note

      You must add at least one user matching rule, and additionally ensure that your users have the required values mapped in their User Profile. See Edit, delete, unlock, and disable users.

  4. Enter the Mandatory Policy OIDs. Separate each OID on a new line.

  5. Enter the Prohibited Policy OIDs. Separate each OID on a new line.

    note

    The Policy OIDs ensure that only certificates with the appropriate policies can be used.

  6. Click Save.

  7. Optional: Click to display the Reorder Matching Rules dialog box.

  8. Click and drag to reorder the user matching rules.

  9. Optional: Click to delete a user matching rule.

Validate your changes

After saving settings, validate the result.

  1. Confirm user matching rules are saved and displayed in the expected order.
  2. Confirm users have the required mapped profile attributes.
  3. Test sign-in with a certificate that should match, and confirm authentication succeeds.
  4. Test with a certificate that violates mandatory or prohibited policy OIDs, and confirm authentication is denied.