value to specify which
field in the certificate will contain the user’s identification
information.
If you plan to configure the portal or gateways to authenticate users
with only certificates, you must specify the Username
Field. This enables GlobalProtect to associate a
username with the certificate.
If you plan to set up the portal or gateway for two-factor
authentication, you can leave the default value of
None, or, to add an additional layer of
security, specify a username. If you specify a username, your
external authentication service verifies that the username in the
client certificate matches the username requesting authentication.
This ensures that the user is the one to which the certificate was
issued.
Users cannot change the username that is included in the
certificate.