11-25
[Sysname-pki-domain-1] root-certificate fingerprint sha1
D1526110AAD7527FB093ED7FC037B0B3CDDDAD93
rule (access control policy view)
Syntax
rule
[
id
] {
deny
|
permit
}
group-name
undo rule
{
id
|
all
}
View
Access control policy view
Default Level
2: System level
Parameters
id
: Number of the certificate attribute access control rule, in the range 1 to 16. The default is the
smallest unused number in this range.
deny
: Indicates that a certificate whose attributes match an attribute rule in the specified attribute
group is considered invalid and denied.
permit
: Indicates that a certificate whose attributes match an attribute rule in the specified attribute
group is considered valid and permitted.
group-name
: Name of the certificate attribute group to be associated with the rule, a case-insensitive
string of 1 to 16 characters. It cannot be “a”, “al” or “all”.
all
: Specifies all access control rules.
Description
Use the
rule
command to create a certificate attribute access control rule.
Use the
undo rule
command to delete a specified or all access control rules.
By default, no access control rule exists.
Note that a certificate attribute group must exist to be associated with a rule.
Examples
# Create an access control rule, specifying that a certificate is considered valid when it matches an
attribute rule in certificate attribute group mygroup.
<Sysname> system-view
[Sysname] pki certificate access-control-policy mypolicy
[Sysname-pki-cert-acp-mypolicy] rule 1 permit mygroup
state
Syntax
state state-name
undo state
Содержание E4510-48G
Страница 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Страница 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Страница 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Страница 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Страница 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Страница 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Страница 857: ...iii 7 Track Configuration Commands 7 1 Track Configuration Commands 7 1 display track 7 1 track nqa 7 2 ...
Страница 914: ...5 17 Sysname reset oam ...
Страница 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Страница 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...