Checking Certificates for Rule Coverage 
You have an X.509 certificate saved as a file.
You have the required authorizations.
For more information, see Rule-Based Certificate Mapping.
Start Rule-based Certificate Mapping (transaction CERTRULE).
Choose
(Import certificate).
Check the results in the Certificate Status Based on Persistence section.
The display indicates whether the certificate can be mapped with a rule or an explicit mapping. If the system can map the certificate, the display indicates the user ID or alias the system reads from the certificate and whether such a user exists in the system.
If the system cannot map the certificate to a rule or exception, you must decide whether you want to create a new rule or exception for the certificate.
If the system can map the certificate, you can choose
(Position, other entry) to jump to the relevant mapping source.