7-14
Cisco AnyConnect VPN Client Administrator Guide
OL-12950-012
Chapter 7 Configuring and Using AnyConnect Client Operating Modes and User Profiles
Configuring Profile Attributes
The profile can contain none or more matching criteria. A certificate must match all specified criteria to
be considered a matching certificate. Distinguished Name matching offers additional match criteria,
including the ability for the administrator to specify that a certificate must or must not have the specified
string, as well as whether wild carding for the string should be allowed. See Appendix A, “Sample
AnyConnect Profile and XML Schema,” for an example.
Ta b l e 7-4 Criteria for Certificate Distinguished Name Mapping
Identifier Description
CN SubjectCommonName
SN SubjectSurName
GN SubjectGivenName
N SubjectUnstructName
I SubjectInitials
GENQ SubjectGenQualifier
DNQ SubjectDnQualifier
C SubjectCountry
L SubjectCity
SP SubjectState
ST SubjectState
O SubjectCompany
OU SubjectDept
T SubjectTitle
EA SubjectEmailAddr
ISSUER-CN IssuerCommonName
ISSUER-SN IssuerSurName
ISSUER-GN IssuerGivenName
ISSUER-N IssuerUnstructName
ISSUER-I IssuerInitials
ISSUER-GENQ IssuerGenQualifier
ISSUER-DNQ IssuerDnQualifier
"SSUER-C IssuerCountry
ISSUER-L IssuerCity
ISSUER-SP IssuerState
ISSUER-ST IssuerState
ISSUER-O IssuerCompany
ISSUER-OU IssuerDept
ISSUER-T IssuerTitle
ISSUER-EA IssuerEmailAddr