35-53
Cisco ASDM User Guide
OL-16647-01
Chapter 35 General
Mapping Certificates to IPSec or SSL VPN Connection Profiles
Add/Edit Certificate Matching Rule Criterion
Use the Add/Edit Certificate Matching Rule Criterion dialog box to configure a certificate matching
rule criterion for the selected group.
Fields
Rule Priority—(Display only). Sequence with which the security appliance evaluates the map when
it receives a connection request. The security appliance evaluates each connection against the map
with the lowest priority number first.
Mapped to Group—(Display only). Connection profile to which the rule is assigned.
Field—Select the part of the certificate to be evaluated from the drop-down list.
Subject—The person or system that uses the certificate. For a CA root certificate, the Subject
and Issuer are the same.
Alternative Subject—The subject alternative names extension allows additional identities to
be bound to the subject of the certificate.
Issuer—The CA or other entity (jurisdiction) that issued the certificate.
Component—(Applies only if Subject of Issuer is selected.) Select the distinguished name
component used in the rule:
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——
DN Field Definition
Whole Field The entire DN.
Country (C) The two-letter country abbreviation. These codes conform to ISO 3166
country abbreviations.
Common Name (CN) The name of a person, system, or other entity. This is the lowest (most
specific) level in the identification hierarchy.
DN Qualifier (DNQ) A specific DN attribute.
E-mail Address (EA) The e-mail address of the person, system or entity that owns the certificate.
Generational Qualifier
(GENQ)
A generational qualifier such as Jr., Sr., or III.
Given Name (GN) The first name of the certificate owner.
Initials (I) The first letters of each part of the certificate owner’s name.
Locality (L) The city or town where the organization is located.
Name (N) The name of the certificate owner.
Organization (O) The name of the company, institution, agency, association, or other entity.
Organizational Unit
(OU)
The subgroup within the organization.
Serial Number (SER) The serial number of the certificate.