8-78
User Guide for Cisco Secure Access Control System 5.4
OL-26225-01
Chapter8 Managing Users and Identity Stores
Configuring Identity Store Sequences
Attribute Retrieval Sequence
You can optionally define a list of databases from which to retrieve additional attributes. These databases
can be accessed regardless of whether you use password or certificate-ba sed authentication. When you
use certificate-based authentication, ACS populates the username field from a certificate attribute and
then uses the username to retrieve attributes.
ACS can retrieve attributes for a user, even when:
The user’s password is flagged for a mandatory change.
The user’s account is disabled.
When you perform password-based authentication, you can define the same identity database in the
authentication list and the attribute retrieval list. However, if the database is used for authentication, it
will not be accessed again as part of the attribute retrieval flow.
ACS authenticates a user or host in an identity store only when there is a single match for that user or
host. If an external database contains multiple instances of the same user, authentication fails. Similarly,
ACS retrieves attributes only when a single match for the user or host exists; otherwise, ACS skips
attribute retrieval from that database.
This section contains the following topics:
Creating, Duplicating, and Editing Identity Store Sequences, page8-78
Deleting Identity Store Sequences, page8-80
Creating, Duplicating, and Editing Identity Store Sequences
To create, duplicate, or edit an identity store sequence:
Step1 Select Users and Identity Stores > Identity Store Sequences.
The Identity Store Sequences page appears.
Step2 Do one of the following:
Click Create.
Check the check box next to the sequence that you wa nt to duplicate, then click Duplicate.
Click the sequence name that you want to modify, or check the check box next to the name and click
Edit.
The Identity Store Sequence Properties page appears as described in Table 8 -25.
Table8-25 Identity Store Sequence Properties Page
Option Description
General
Name Enter the name of the identity store sequence.
Description Enter a description of the identity store sequence.
Authentication Method List
Certificate Based Check this check box to use the certificate-based authentication method. If you choose this
option, you must enter the certificate authentication profile. Click Select to choose the profile
from a list of available profiles.