Adding and Activating X.509 Certificate Parameters for X.509 Certificate Parameter Authentication
Starting with Junos Space Network Management Platform Release 15.2R1, you can add X.509 certificate parameters to authenticate users by using X.509 certificate parameters. You must enable X.509 certificate parameter authentication mode on the Modify Application Settings page to use this authentication mode. You can add up to four parameters to authenticate users in this authentication mode. You can specify X.509 certificate parameters such as CN (common name), OU (organizational unit), O (organization), L (location), ST (state of residence), C (country of residence), EMAILADDRESS (e-mail address), rfc822Name (e-mail address of the user extracted from the subject alternative name), and msUPN (Microsoft User Principal Name). The display names you specified when creating these parameters are displayed on the Create User page when you specify the values for the parameters. For more information, see Creating Users in Junos Space Network Management Platform.
If you are adding a new parameter with the parameter-based authentication enabled, all users are locked if you activate the parameter without specifying the values of the parameter for all users. This restriction does not apply when you add parameters with the password-based or complete certificate-based authentication mode enabled.
The following topics describe how to add and activate X.509 certificate parameters.
Adding X.509 Certificate Parameters for X.509 Certificate Parameter Authentication
You add X.509 certificate parameters to authenticate users by using X.509 certificate parameters.
To add an X.509 certificate parameter:
Activating an X.509 Certificate Parameter
If you are authenticating users by using the parameter-based authentication mode and adding a new parameter, you must deactivate the parameter and enter the value of the parameter for all Junos Space Platform users from the Modify User page before activating the parameter for authentication. For more information, refer to Modifying a User.
To activate an X.509 certificate parameter: