Operation Manual – SSL-HTTPS
H3C S3610&S5510 Series Ethernet Switches
Chapter 2 HTTPS Configuration
2-4
Note:
z
If the
ip https certificate access-control-policy
command is executed repeatedly,
the HTTPS server is only associated with the last specified certificate attribute
access control policy.
z
If the HTTPS service is associated with a certificate attribute access control policy,
the
client-verify enable
command must be configured in the SSL server policy.
Otherwise, the client cannot log onto the device.
z
If the HTTPS service is associated with a certificate attribute access control policy,
the latter must contain at least one
permit
rule. Otherwise, no HTTPS client can log
onto the device.
z
For the configuration of an SSL server policy, refer to
PKI Configuration
.
2.6 Associating the HTTPS Service with an ACL
Associating the HTTPS service with an ACL can filter out requests from some clients to
let pass only clients that pass the ACL filtering.
Follow these steps to associate the HTTPS service with an ACL:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Associate the HTTPS
service with an ACL
ip https acl acl-number
Required
Not associated by default.
Note:
If the
ip https acl
command is executed repeatedly, the HTTPS service is only
associated with the last specified ACL.
2.7 Displaying and Maintaining HTTPS
To do…
Use the command…
Remarks
Display information about
HTTPS
display ip https
Available in any view