![H3C S5120-SI Series Скачать руководство пользователя страница 427](http://html2.mh-extra.com/html/h3c/s5120-si-series/s5120-si-series_operation-manual_3711174427.webp)
1-12
To do…
Use the command…
Remarks
Enter system view
system-view
—
Delete certificates
pki delete-certificate
{
ca
|
local
}
domain
domain
-
name
Required
Configuring an Access Control Policy
By configuring a certificate attribute-based access control policy, you can further control access to the
server, providing additional security for the server.
Follow these steps to configure a certificate attribute-based access control policy:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a certificate attribute
group and enter its view
pki certificate attribute-group
group-name
Required
No certificate attribute group
exists by default.
Configure an attribute rule for
the certificate issuer name,
certificate subject name, or
alternative subject name
attribute
id
{
alt-subject-name
{
fqdn
|
ip
} | {
issuer-name
|
subject-name
} {
dn
|
fqdn
|
ip
} } {
ctn
|
equ
|
nctn
|
nequ
}
attribute-value
Optional
There is no restriction on the
issuer name, certificate subject
name and alternative subject
name by default.
Return to system view
quit
—
Create a certificate
attribute-based access control
policy and enter its view
pki certificate
access-control-policy
policy-name
Required
No access control policy exists
by default.
Configure a certificate
attribute-based access control
rule
rule
[
id
] {
deny
|
permit
}
group-name
Required
No access control rule exists by
default.
A certificate attribute group must exist to be associated with a rule.
Displaying and Maintaining PKI
To do…
Use the command…
Remarks
Display the contents or request
status of a certificate
display pki certificate
{ {
ca
|
local
}
domain
domain-name
|
request-status
}
Available in any view
Display CRLs
display pki crl domain
domain-name
Available in any view
Содержание S5120-SI Series
Страница 61: ...7 8 Sysname ip http acl 2030...
Страница 138: ...2 10 PORT VLAN MODE GigabitEthernet1 0 1 2 MANUAL...
Страница 186: ...1 46 Instance Vlans Mapped 0 1 to 9 11 to 19 21 to 29 31 to 4094 1 10 2 20 3 30...
Страница 218: ...ii Displaying and Maintaining BOOTP Client Configuration 4 2 BOOTP Client Configuration Example 4 3...
Страница 255: ...1 12...
Страница 381: ...ii Troubleshooting RADIUS 1 32...
Страница 577: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...