Avatar of Manny Fernandez
Manny Fernandez
 asked on

Generating User Certificates with a sAMAccountName as the CN

I am configuring 802.1x for a wireless deployment.  I am using Microsoft CA Services to do auto-enroll for user certificates.  The problem I am having is that the template I cloned (the user template), generates the CN as the "Display Name" (e.g. John Doe) what I would like for it to use is the sAMAccountName (e.g. jdoe).  The issue is that if I do `display name`, the user would need to type "John Doe" for the EAP while everything else would be `Jdoe`.  Does anyone know of a way to do this?  We are using FortiAuthenticator as the RADIUS server.  

Side note, I was able to get it working using the FortiAuthenticator as the CA but I cannot use GPO to auto-enroll the users so it makes it more complex.
Active Directory* ca

Avatar of undefined
Last Comment
arnold

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Mahesh

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
arnold

Are your 802.1x depends on the user or the system?
Are these domain based machines or personal devices that a user brings in?
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes