| 
 | 
 | 
 | Appendix D: CPL Substitutions | 
| 
 | 
 | 
 | 
 | 
| 
 | Category: user | 
 | 
 | 
| 
 | 
 | 
 | 
 | 
| 
 | ELFF | CPL | Description | 
| 
 | 
 | 
 | 
 | 
| 
 | group | One group that an authenticated client is a | |
| 
 | 
 | 
 | member of. The group selected is determined | 
| 
 | 
 | 
 | by either a group.log_order definition in | 
| 
 | 
 | 
 | policy or the order groups are referenced in | 
| 
 | 
 | 
 | policy | 
| 
 | 
 | 
 | 
 | 
| 
 | groups | Groups that an authenticated client is a | |
| 
 | 
 | 
 | member of. | 
| 
 | 
 | ||
| 
 | 
 | 
 | BASIC, NTLM, LDAP) | 
| 
 | realm | Authentication realm that the user was | |
| 
 | 
 | 
 | challenged in. | 
| 
 | user | Full username of a client authenticated to the | |
| 
 | 
 | 
 | proxy (fully distinguished). | 
| 
 | user.name | Relative username of a client authenticated to | |
| 
 | 
 | 
 | the proxy; for example, not fully | 
| 
 | 
 | 
 | distinguished. | 
| 
 | 
 | 
 | 
 | 
| 
 | 
 | ||
| 
 | 
 | Relative username of a client authenticated to | |
| 
 | 
 | 
 | the proxy; for example, not fully | 
| 
 | 
 | 
 | distinguished (same as  | 
| 
 | 
 | Used to identify the user using either their | |
| 
 | 
 | 
 | authenticated proxy username or, if that is | 
| 
 | 
 | 
 | unavailable, their IP address. | 
| 
 | 
 | 
 | 
 | 
| 
 | 
 | Session ID made available through RADIUS | |
| 
 | 
 | when configured for session management | |
| 
 | 
 | 
 | |
| 
 | 
 | Username made available through RADIUS | |
| 
 | username | 
 | when configured for session management | 
| 
 | user.x509.issuer | If the user was authenticated through an | |
| 
 | 
 | 
 | X.509 certificate, this is the issuer of the | 
| 
 | 
 | 
 | certificate as an RFC2253 DN. | 
| 
 | 
 | 
 | 
 | 
| 
 | user.x509.serialNumber | If the user was authenticated through an | |
| 
 | number | 
 | X.509 certificate, this is the serial number | 
| 
 | 
 | 
 | from the certificate as a hexadecimal number. | 
| 
 | user.x509.subject | If the user was authenticated through an | |
| 
 | 
 | 
 | X.509 certificate, this is the subject of the | 
| 
 | 
 | 
 | certificate as an RFC2253 DN. | 
| 
 | 
 | 
 | 
 | 
| 
 | 
 | 
 | 
 | 
| 
 | Category: ci_request_header | 
 | 
 | 
| 
 | 
 | 
 | 
 | 
| 
 | ELFF | CPL | Description | 
| 
 | 
 | 
 | 
 | 
| 
 | cs(Accept) | request.header.Accept | Request header: Accept | 
| 
 | request.header.Accept- | Request header:  | |
| 
 | 
 | Charset | 
 | 
| 
 | request.header.Accept- | Request header:  | |
| 
 | 
 | Encoding | 
 | 
293
