409
Default
No certificate-based access control policies exist.
Views
System view
Predefined user roles
network-admin
mdc-admin
Parameters
policy-name
: Specifies a policy name, a case-insensitive string of 1 to 31 characters.
Usage guidelines
A certificate-based access control policy contains a set of access control rules that permit or deny
access to the device based on the attributes in the requesting client's certificate.
Examples
# Create a certificate-based access control policy named
mypolicy
and enter its view.
<Sysname> system-view
[Sysname] pki certificate access-control-policy mypolicy
[Sysname-pki-cert-acp-mypolicy]
Related commands
display pki certificate access-control-policy
rule
pki certificate attribute-group
Use
pki certificate attribute-group
to create a certificate attribute group and enter its view, or enter
the view of an existing certificate attribute group.
Use
undo pki certificate attribute-group
to remove a certificate attribute group.
Syntax
pki certificate attribute-group group-name
undo pki certificate attribute-group
group-name
Default
No certificate attribute groups exist.
Views
System view
Predefined user roles
network-admin
mdc-admin
Parameters
group-name
: Specifies a group name, a case-insensitive string of 1 to 31 characters.