In most clusters with a mix of platforms, the choices are to use self-signed certificates, write a CHAD exit, or live without the ability to revoke access per distinguished name.
Some of these properties point to literal values (like names) while others point to other objects [like work locations specified by distinguished names (DN)].