The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Setting up your environment using the Subject field

Prev Next

This example shows setting up your environment using the Subject field.

  • The user has a token that supports the Read Username from Smartcard feature.

  • The user wants to log on asUser1, which is the Drive Encryption user name.

  • The user name that the user wants to log on as (User1) resides in the Subject field on the certificate (for example: CN=User1,DC=DomainComponent,DC=com).

  • Therefore, under ePO - On-prem Logon Product Settings, the user should select Subject as the certificate field that contains the user name.

  • Because the user wants to match the whole certificate field, deselect Match certificate username field up to the @ sign.

  • The user should check their DE LDAP Sync Task User Name attribute field in ePO - On-prem. In this situation, distinguishedname is the correct field to use because it contains the exact same information as the cert field Subject, so a valid comparison can be made.

  • Finally, the user should run their DE LDAP Sync Task, and synch their product policy on the system where they want to use the Read Username from Smartcard feature.

Note

It is essential to understand that the distinguishedname LDAP attribute is now used. If the user ever has to log on manually at the Pre-Boot Authentication stage, the user must type the distinguished name in the User name field (for example, CN=User1,DC=DomainComponent,DC=com).