
Operation Manual – PKI
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 PKI Configuration
1-12
To do…
Use the command…
Remarks
Set the CRL update
period
crl update-period
hours
Optional
By default, the CRL
update period depends on
the next update field in the
CRL file.
Enable CRL checking
crl check
enable
Optional
Enabled by default
Return to system view
quit
—
Retrieve the CA certificate
Required
Retrieve CRLs
pki retrieval-crl domain
domain-name
Required
Verify the validity of a
certificate
pki validate-certificate
{
ca
|
local
}
domain
domain-name
Required
II. Configuring CRL-checking-disabled PKI certificate validation
Follow these steps to configure CRL-checking-disabled PKI certificate validation:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter PKI domain view
pki domain domain-name
—
Disable CRL checking
crl check
disable
Required
Enabled by default
Return to system view
quit
—
Retrieve the CA certificate
Required
Verify the validity of the
certificate
pki validate-certificate
{
ca
|
local
}
domain
domain-name
Required