Working in the CLI
Cluster 'proto'
Flag
Description
ignore_critical_extns
Control whether Equalizer will process "CRL Distribution
Point" extensions in client certificates. This option only
affects the processing of the "CRL Distribution Point"
extension in client certificates:
When
Ignore Critical Extensions
is disabled, a client
certificate presented to Equalizer that includes any
extension will be rejected by Equalizer. This is the
behavior in previous releases.
When
Ignore Critical Extensions
is enabled (the
default), a client certificate presented to Equalizer that
has a CRL Distribution Point extension will be processed
and the CRL critical extension will be ignored. Note,
however, that if other extensions are present in a client
certificate they are not ignored and will cause the client
certificate to be rejected by Equalizer.
strict_crl_chain
Check the validity of all certificates in a certificate chain
against the CRL associated with the cluster. If any of the
certificates in the chain cannot be validated, return an
error. If this option is
disabled
(the default), only the last
certificate in the chain is checked for validity.
176
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......