
1-11
Deleting a Certificate
When a certificate requested manually is about to expire or you want to request a new certificate, you
can delete the current local certificate or CA certificate.
Follow these steps to delete a certificate:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Delete certificates
pki delete-certificate
{
ca
|
local
}
domain
domain
-
name
Required
Configuring an Access Control Policy
By configuring a certificate attribute-based access control policy, you can further control access to the
server, providing additional security for the server.
Follow these steps to configure a certificate attribute-based access control policy:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a certificate attribute group
and enter its view
pki certificate attribute-group
group-name
Required
No certificate attribute group exists
by default.
Configure an attribute rule for the
certificate issuer name, certificate
subject name, or alternative
subject name
attribute
id
{
alt-subject-name
{
fqdn
|
ip
} | {
issuer-name
|
subject-name
} {
dn
|
fqdn
|
ip
} }
{
ctn
|
equ
|
nctn
|
nequ
}
attribute-value
Optional
There is no restriction on the issuer
name, certificate subject name and
alternative subject name by
default.
Return to system view
quit
—
Create a certificate attribute-based
access control policy and enter its
view
pki certificate
access-control-policy
policy-name
Required
No access control policy exists by
default.
Configure a certificate
attribute-based access control rule
rule
[
id
] {
deny
|
permit
}
group-name
Required
No access control rule exists by
default.
A certificate attribute group must exist to be associated with a rule.
Displaying and Maintaining PKI
To do…
Use the command…
Remarks
Display the contents or request
status of a certificate
display pki certificate
{ {
ca
|
local
}
domain
domain-name
|
request-status
}
Available in any view
Display CRLs
display pki crl domain
domain-name
Available in any view
Содержание S5120-EI Series
Страница 139: ...ii...
Страница 268: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 328: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 578: ...1 21 C...
Страница 739: ...1 12 Enable ARP detection based on 802 1X security entries SwitchB arp detection mode dot1x...
Страница 926: ...2 8...
Страница 942: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5...
Страница 985: ...1 1...
Страница 1018: ...1 6...