236
pki validate-certificate
Syntax
pki validate-certificate
{
ca
|
local
}
domain
domain-name
View
System view
Default level
2: System level
Parameters
ca
: Verifies the CA certificate.
local
: Verifies the local certificate.
domain-name
: Specifies the name of the PKI domain to which the certificate to be verified belongs, a
string of 1 to 15 characters.
Description
Use the
pki validate-certificate
command to verify the validity of a certificate.
The focus of certificate validity verification will check that the certificate is signed by the CA and that the
certificate has neither expired nor been revoked.
Related commands:
pki domain
.
Examples
# Verify the validity of the local certificate.
<Sysname> system-view
[Sysname] pki validate-certificate local domain 1
root-certificate fingerprint
Syntax
root-certificate fingerprint
{
md5
|
sha1
}
string
undo root-certificate fingerprint
View
PKI domain view
Default level
2: System level
Parameters
md5
: Uses an MD5 fingerprint.
sha1
: Uses a SHA1 fingerprint.
string
: Specifies the fingerprint to be used. An MD5 fingerprint must be a string of 32 characters in
hexadecimal. A SHA1 fingerprint must be a string of 40 characters in hexadecimal.
Description
Use the
root-certificate fingerprint
command to configure the fingerprint to be used for verifying the
validity of the CA root certificate.