![H3C S5120-SI Series Скачать руководство пользователя страница 436](http://html2.mh-extra.com/html/h3c/s5120-si-series/s5120-si-series_operation-manual_3711174436.webp)
1-21
[Switch-pki-cert-attribute-group-mygroup1] quit
# Create certificate attribute group
mygroup2
and add two attribute rules. The first rule defines that the
FQDN of the alternative subject name does not include the string of
apple
, and the second rule defines
that the DN of the certificate issuer name includes the string
aabbcc
.
[Switch] pki certificate attribute-group mygroup2
[Switch-pki-cert-attribute-group-mygroup2] attribute 1 alt-subject-name fqdn nctn apple
[Switch-pki-cert-attribute-group-mygroup2] attribute 2 issuer-name dn ctn aabbcc
[Switch-pki-cert-attribute-group-mygroup2] quit
3) Configure the certificate attribute-based access control policy
# Create the certificate attribute-based access control policy of
myacp
and add two access control
rules.
[Switch] pki certificate access-control-policy myacp
[Switch-pki-cert-acp-myacp] rule 1 deny mygroup1
[Switch-pki-cert-acp-myacp] rule 2 permit mygroup2
[Switch-pki-cert-acp-myacp] quit
4) Apply the SSL server policy and certificate attribute-based access control policy to HTTPS service
and enable HTTPS service.
# Apply SSL server policy
myssl
to HTTPS service.
[Switch] ip https ssl-server-policy myssl
# Apply the certificate attribute-based access control policy of
myacp
to HTTPS service.
[Switch] ip https certificate access-control-policy myacp
# Enable HTTPS service.
[Switch] ip https enable
Troubleshooting PKI
Failed to Retrieve a CA Certificate
Symptom
Failed to retrieve a CA certificate.
Analysis
Possible reasons include these:
z
The network connection is not proper. For example, the network cable may be damaged or loose.
z
No trusted CA is specified.
z
The URL of the registration server for certificate request is not correct or not configured.
z
No authority is specified for certificate request.
z
The system clock of the device is not synchronized with that of the CA.
Solution
z
Make sure that the network connection is physically proper.
z
Check that the required commands are configured properly.
z
Use the
ping
command to check that the RA server is reachable.
z
Specify the authority for certificate request.
z
Synchronize the system clock of the device with that of the CA.
Содержание S5120-SI Series
Страница 61: ...7 8 Sysname ip http acl 2030...
Страница 138: ...2 10 PORT VLAN MODE GigabitEthernet1 0 1 2 MANUAL...
Страница 186: ...1 46 Instance Vlans Mapped 0 1 to 9 11 to 19 21 to 29 31 to 4094 1 10 2 20 3 30...
Страница 218: ...ii Displaying and Maintaining BOOTP Client Configuration 4 2 BOOTP Client Configuration Example 4 3...
Страница 255: ...1 12...
Страница 381: ...ii Troubleshooting RADIUS 1 32...
Страница 577: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...