crypto-local pki rcp
crypto-local pki rcp
<name> [crl-location <file>]|[enable-ocsp-responder]|[ocsp-responder-cert <ocsp-responder-
cert>]|[ocsp-signer-cert <ocsp-signer-cert>]|
[ocsp-url <ocsp-url>]|[revocation-check [None|<method1>|<method2>]]
Description
Use this command to specify the certificates used to sign OCSP for the revocation check point.
Syntax
Parameter
Description
rcp
Specifies the revocation check point. A revocation checkpoint is
automatically created when a TrustedCA or IntermediateCA certificate
is imported on the controller.
crl-location <file>
Location of the CRL that is used for the rcp. The specified CRL filename
must be previously imported onto the controller before using this
option.
enable-ocsp-responder
Enables the OCSP Responder for this revocation checkpoint. The
default is disabled.
ocsp-responder-cert <ocsp-
responder-cert>
Specifies the certificate that is used to verify OCSP responses. The
certificate name has to be one of the certificates shown as output
when the CLI command
show crypto-local pki ocsprespondercert
is used.
ocsp-signer-cert <ocsp-signer-
cert>
Specifies the certificate that is used to sign OCSP responses for this
revocation check point. The OCSP signer certificate must be previously
imported on to the controller (using the WebUI). The OCSP signer cert
can be the same trusted CA as the check point, a designated OCSP
signer certificate issued by the same CA as the check point or some
other local trusted authority.
If the ocsp-signer-cert is not specified, OCSP responses are signed
using the global OCSP signer certificate. If that is not present, than an
error message is sent out to clients.
NOTE: The OCSP signer certificate (if configured) takes precedence
over the global OCSP signer certificate as this is check point specific.
ocsp-url <ocsp-url>
Configures the OCSP Server URL. The URL has to be in the form of
http://my.responder.com/path. This parameter can contain only one
responder URL at time.
revocation-check None <method1>
<method2>
Configures the revocation check methods used for this rcp. Options
include:
l
None (default)- No revocation checks are performed for certificates
being verified against this trusted CA.
l
CRL- CRL is used for the revocation check method.
l
OCSP- OCSP is used for the revocation check method.
You can configure one fallback method.
Dell PowerConnect W-Series ArubaOS 6.2 |
Reference Guide
crypto-local pki rcp | 233
Содержание PowerConnect W-7200 Series
Страница 1: ...Dell PowerConnect W Series ArubaOS 6 2 Command Line Interface Reference Guide ...
Страница 38: ...38 aaa authentication server windows DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Страница 319: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide interface loopback 319 ...
Страница 346: ...346 ipv6 mld DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Страница 387: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide ip radius 387 ...
Страница 995: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide show firewall 995 ...
Страница 1070: ...1070 show ip dhcp DellPowerConnect W Series ArubaOS 6 2 Reference Guide Command History Introduced in ArubaOS 3 0 ...
Страница 1529: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide wms client 1529 ...
Страница 1536: ...0510956 01 March 2013 1536 ...