1-20
Configuring a Certificate Attribute-Based Access Control Policy
Network requirements
z
The client accesses the remote HTTP Security (HTTPS) server through the HTTPS protocol.
z
SSL is configured to ensure that only legal clients log into the HTTPS server.
z
Create a certificate attribute-based access control policy to control access to the HTTPS server.
Figure 1-4
Configure a certificate attribute-based access control policy
Configuration procedure
z
For detailed information about SSL configuration, refer to
SSL Configuration
in the
Security
Volume
.
z
For detailed information about HTTPS configuration, refer to
HTTP Configuration
in the
System
Volume
.
z
The PKI domain to be referenced by the SSL policy must be created in advance. For detailed
configuration of the PKI domain, refer to
1) Configure the HTTPS server
# Configure the SSL policy for the HTTPS server to use.
<Switch> system-view
[Switch] ssl server-policy myssl
[Switch-ssl-server-policy-myssl] pki-domain 1
[Switch-ssl-server-policy-myssl] client-verify enable
[Switch-ssl-server-policy-myssl] quit
2) Configure the certificate attribute group
# Create certificate attribute group
mygroup1
and add two attribute rules. The first rule defines that the
DN of the subject name includes the string
aabbcc
, and the second rule defines that the IP address of
the certificate issuer is 10.0.0.1.
[Switch] pki certificate attribute-group mygroup1
[Switch-pki-cert-attribute-group-mygroup1] attribute 1 subject-name dn ctn aabbcc
[Switch-pki-cert-attribute-group-mygroup1] attribute 2 issuer-name ip equ 10.0.0.1
[Switch-pki-cert-attribute-group-mygroup1] quit
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...