Use the CLI commands in this section to enable or disable the LDAP server that is used to authorize users that are already authenticated using the X.509 certificate.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable the LDAP server to map a remote user to a local user account for certificate-based authentication.
hostname (config) # aaa authorization certificate map-ldap enableVerify the status of the LDAP server.
hostname (config) # show aaa authorization certificateCertificate based authorization settings:
LDAP enabled : yes
.....
Save your changes.
hostname (config) # write memory
Go to CLI configuration mode.
hostname > enablehostname # configure terminalDisable the LDAP server that is used for authorization.
hostname (config) # no aaa authorization certificate map-ldap enableVerify the status of the LDAP server.
hostname (config) # show aaa authorization certificateCertificate based authorization settings:
LDAP enabled : no
.....
Save your changes.
hostname (config) # write memory