NOTE:
If you have an IPv6 address in the URL, then enclose this address in square brackets. For example, http://
[1100::203]:6514.
Configuring OCSP behavior
You can configure how the OCSP requests and responses are signed when the CA or the device contacts the OCSP responders.
To configure this behavior, follow this step:
In CONFIGURATION mode, enter the following command:
crypto x509 ocsp {[nonce] [sign-request]}
Both the
none
and
sign-request
parameters are optional. The default behavior is to not use these two options. If your OCSP
responder uses pre-computed responses, you cannot use the
none
feature in the switch's communcations with the responder. If your
OCSP responder requires signed requests, you can use the
sign-requests
option.
Configuring Revocation Behavior
You can configure the system behavior if an OCSP responder fails.
By default, when all the OCSP responders fail to send a response to an OSCP request, the system accepts the certificate and logs the
event. However, you can configure the system to reject the certificate in case OCSP responders fail.
To configure OCSP revocation settings:
In CONFIGURATION mode, enter the following command:
crypto x509 revocation
ocsp
[accept | reject]
The default behavior is to accept certificates if either an OCSP responder is unavailable or if no responder is identified.
Configuring OSCP responder preference
You can configure the preference or order that the CA or a device follows while contacting multiple OCSP responders.
Enter the following command in Certificate mode:
ocsp-server prefer
Verifying certificates
A CA certificate’s public key is used to decrypt a presented certificate’s signature to obtain a hash value.
The rest of the presented certificate is also hashed and if the two hashes match then the certificate is considered valid.
During verification, the system checks the presented certificates for revocation information. The system also enables you to configure
behavior in case a certificate’s revocation status cannot be verified; for example, when the OCSP responder is unreachable you can alter
system behavior to accept or reject the certificate depending on configuration. The default behavior is to accept the certificates. The
system also logs the events where the OSCP responders fail or invalid OSCP responses are received.
NOTE:
A CA certificate can also be
revoked.
X.509v3
1145
Содержание S4048T-ON
Страница 1: ...Dell Configuration Guide for the S4048 ON System 9 11 2 1 ...
Страница 148: ...Figure 10 BFD Three Way Handshake State Changes 148 Bidirectional Forwarding Detection BFD ...
Страница 251: ...Dell Control Plane Policing CoPP 251 ...
Страница 363: ... RPM Synchronization GARP VLAN Registration Protocol GVRP 363 ...
Страница 511: ...Figure 64 Inspecting the LAG Configuration Link Aggregation Control Protocol LACP 511 ...
Страница 512: ...Figure 65 Inspecting Configuration of LAG 10 on ALPHA 512 Link Aggregation Control Protocol LACP ...
Страница 515: ...Figure 67 Inspecting a LAG Port on BRAVO Using the show interface Command Link Aggregation Control Protocol LACP 515 ...
Страница 516: ...Figure 68 Inspecting LAG 10 Using the show interfaces port channel Command 516 Link Aggregation Control Protocol LACP ...
Страница 558: ...Figure 84 Configuring Interfaces for MSDP 558 Multicast Source Discovery Protocol MSDP ...
Страница 559: ...Figure 85 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 559 ...
Страница 560: ...Figure 86 Configuring PIM in Multiple Routing Domains 560 Multicast Source Discovery Protocol MSDP ...
Страница 564: ...Figure 88 MSDP Default Peer Scenario 2 564 Multicast Source Discovery Protocol MSDP ...
Страница 565: ...Figure 89 MSDP Default Peer Scenario 3 Multicast Source Discovery Protocol MSDP 565 ...
Страница 729: ...protocol spanning tree pvst no disable vlan 300 bridge priority 4096 Per VLAN Spanning Tree Plus PVST 729 ...
Страница 841: ...Figure 115 Single and Double Tag TPID Match Service Provider Bridging 841 ...
Страница 842: ...Figure 116 Single and Double Tag First byte TPID Match 842 Service Provider Bridging ...