OmniVista Cirrus 10.6.1 Documentation

Certificate Local Authorization Rules

When an Access Policy uses the local database for authentication and EAP-TLS as the method, UPAM must support a local authorization method. Local authorization evaluates certificate-attribute-based rules against the authenticated client certificate to determine the network enforcement action (accept or reject). The Screen displays all configured certificate-attribute-based rules and is used to create, edit, and delete Certificate local authorization rules.

To access the Certificate Local Authorization Rules screen, click on Auth & Automation > UPAM-NAC > CertAuth Rules under the “Configure” section of the OmniVista Cirrus Menu.

cert auth rules OVC 10.6.1-20260616-130254.png

Creating a New Rule

Click on Create Rule to bring up the New Certificate Local Authorization Rule Screen. Use this screen to define the following attributes for creating a new Rule:

When you are done configuring the attributes for the New Rule, click on Create button.

Basic Information

Basic info create CerAuth Rule OVC 10.6.1-20260617-162726.png
  • Name - Enter a rule name.

  • Precedence - Specify Rule Priority. A user requesting authentication may match several access policies and the one with highest priority will take effect after passing the authentication.
    (Range = 1-99, 1 is the highest priority and 99 is the lowest priority)

Certificate Attribute Condition

Certificate attribute conditions specify what must match for this rule to apply for local authorization. At least one condition is mandatory. When multiple conditions exist, all must match before applying the authorization rule.

Certificate attribute condition create cretauth Rule OVC 10.6.1-20260617-163236.png


  • Attribute - Select the Certificate Attribute from the drop-down list. The list of Attribute Name with Description is given below.

  • Operator - Select a condition operator.

  • Value - Select a condition value. Enter at least one value. A maximum of 32 values are allowed.

Click on Add Condition to add another mapping condition to the Authorization Rule.

Network Enforcement Policy

Create NEP cretauth Rules OVC10.6.1-20260617-165439.png
  • Action - Accept or Reject user authentication with matching certificate attribute based rules.

  • Access Role Profile - Select the Access Role Profile from the drop-down list. If necessary, you can click on Create Access Role Profile to go to the Create Access Role Profile screen to create a profile.

  • Unified Policy List - Select a Unified Policy List from the drop-down list. If necessary, you can click on Create Unified Policy List to go to the Create Unified Policy List screen to create a policy list.

  • Other Attributes - Select the required attributes and provide values.

    • Acct-Interim-Interval - Interval for RADIUS accounting, in seconds. If not configured, the device's default accounting policy will take effect. (Range = 60 - 1200, Default = 600).

    • Session-Timeout - The Session Timeout Interval is the maximum number of consecutive seconds of connection allowed to the user before termination of the session or prompt. If not configured, the device's default session timeout policy will take effect. (Range = 12000 - 86400, Default = 43200).

    • Tunnel-Private -Group-ID - The Tunnel Private Group ID is used to determine the UNP for the device, if applicable. Tunnel Private Group ID is a RADIUS attribute that indicates the group ID for a particular tunnel session. It may be included in the Access-Request packet if the tunnel initiator can pre-determine the group resulting from a particular connection, and should be included in the Access-Accept packet if this tunnel session is to be treated as belonging to a particular private group. In most cases, L2 VLAN domain is a private group, and the Tunnel Group ID is pointing to the VLAN ID. (Range = 1 - 4094)

    • WISPr-Bandwidth-Max-Down - The user downstream bandwidth, in kbit/s. Value must be in range [0 - 2147483]. By default or set it to 0, it is not limited.

    • WISPr-Bandwidth-Max-Up - The user upstream bandwidth, in kbit/s. Value must be in range [0 - 2147483]. By default or set it to 0, it is not limited.

Certificate Attributes List

Attribute Name

Description

O

Organization from certificate Subject DN

C

Country from certificate Subject DN

ST

State from certificate Subject DN

L

Locality from certificate Subject DN

email

Email address from Subject Alternative Name

DNS Name

DNS Name from Subject Alternative Name

Serial Number

Certificate serial number

Issuer

Certificate issuer (full DN

CN

Common Name from certificate Subject DN

OU

Organizational Unit from certificate Subject DN

Editing a Rule

You can edit the parameter values for an existing Certificate Local Authorization Rule by accessing the Edit screen.

edit the rule OVC 10.6.1-20260618-155229.png

Use one of the following methods to access the Edit Certificate Local Authorization Rule screen (as shown above):

  • Select the rule name to edit by clicking on the checkbox next to the rule name, click on Actions, then select Edit from the drop-down menu.

  • Click on the pencil icon under the “Actions” column next to the rule name that you want to edit.

The following Edit screen displays. Edit the fields as described above, then click on Save.

edit Certauth rule screen OVC 10.6.1-20260618-155524.png

You cannot edit the Rule Name.

Deleting a Rule

To delete a Certificate Local Authorization Rule, use one of the following methods to select the rule you want to delete:

  • Select the rule to delete by clicking on the checkbox next to the rule name, click on Actions, then select Delete from the drop-down menu.

  • Click on the trash can icon under the “Actions” column next to the rule name that you want to delete.

delete a rule certauth rule OVC 10.6.1-20260618-161222.png

When you select the rule you want to delete, the following confirmation prompt appears:

delete confirm certauthrule OVC 10.6.1-20260618-161443.png

Click on Delete to confirm that you want to delete the Rule.

Display Certificate Local Authorization Rule

The Certificate Local Authorization Rule list displays information for the certificate attribute based rules. To display detailed information about a specific rule, click on the Additional Information icon under the “Actions” column. The information displayed on this screen is defined below.

display Certauth rule info OVC 10.6.1-20260618-171943.png
  • Name - The name of the Rule.

  • Mapping Condition - Specifies what condition must match for this rule to apply for local authorization. At least one condition is mandatory.

  • Access Role Profile - The name of the Access Role Profile applied for Network Enforcement.

  • Unified Policy List - The name of the Unified Policy List applied for Network Enforcement.

  • Action - Accept or Reject user authentication with matching certificate attribute based rules.

  • Priority - Specifies the Rule Priority.

  • Session Timeout - The maximum number of consecutive seconds of connection allowed to the user before termination of the session or prompt.

  • Accounting Interim Interval - Interval for RADIUS accounting, in seconds.

  • Upstream Bandwidth - The user upstream bandwidth, in kbit/s.

  • Downstream Bandwidth - The user downstream bandwidth, in kbit/s.

  • Created At - The date and time the rule was created.

  • Updated At - The date and time the rule was last updated.

  • Tunnel Private Group ID - The Tunnel Private Group ID is used to determine the UNP for the device, if applicable.