241
# Create certificate attribute group
mygroup2
and add two attribute rules. The first rule defines that the
FQDN of the alternative subject name does not include the string of
apple
, and the second rule defines
that the DN of the certificate issuer name includes the string
aabbcc
.
[Router] pki certificate attribute-group mygroup2
[Router-pki-cert-attribute-group-mygroup2] attribute 1 alt-subject-name fqdn nctn apple
[Router-pki-cert-attribute-group-mygroup2] attribute 2 issuer-name dn ctn aabbcc
[Router-pki-cert-attribute-group-mygroup2] quit
3.
Configure the certificate attribute-based access control policy.
# Create the certificate attribute-based access control policy of
myacp
and add two access control rules.
[Router] pki certificate access-control-policy myacp
[Router-pki-cert-acp-myacp] rule 1 deny mygroup1
[Router-pki-cert-acp-myacp] rule 2 permit mygroup2
[Router-pki-cert-acp-myacp] quit
4.
Apply the SSL server policy and certificate attribute-based access control policy to HTTPS service,
and enable HTTPS service.
# Apply SSL server policy
myssl
to HTTPS service.
[Router] ip https ssl-server-policy myssl
# Apply the certificate attribute-based access control policy of
myacp
to HTTPS service.
[Router] ip https certificate access-control-policy myacp
# Enable HTTPS service.
[Router] ip https enable
Troubleshooting PKI
Failed to retrieve a CA certificate
Symptom
Failed to retrieve a CA certificate.
Analysis
Possible reasons include:
•
The network connection is not proper. For example, the network cable might be damaged or loose.
•
No trusted CA is specified.
•
The URL of the registration server for certificate request is not correct or not configured.
•
No authority is specified for certificate request.
•
The system clock of the router is not synchronized with that of the CA.
Solution
•
Make sure that the network connection is physically proper.
•
Check that the required commands are configured properly.
•
Use
ping
to check that the RA server is reachable.
•
Specify the authority for certificate request.
•
Synchronize the system clock of the router with that of the CA.