Chapter 47 Certificates
ZyWALL / USG (ZLD) CLI Reference Guide
305
cdp {activate|deactivate}
Turns certificate revocation on or off. When it is turned on,
the ZyWALL / USG validates a certificate by getting a
Certificate Revocation List (CRL) through HTTP or LDAP
(can be configured after activating the LDAP checking
option) and online responder (can be configured after
activating the OCSP checking option). You also need to
configure the OSCP or LDAP server details.
ldap {activate|deactivate}
Has the ZyWALL / USG check (or not check) incoming
certificates that are signed by this certificate against a
Certificate Revocation List (CRL) on a LDAP (Lightweight
Directory Access Protocol) directory server.
ldap ip {
ip
|
fqdn
} port <1..65535> [id
name
password
password
] [deactivate]
Sets the validation configuration for the specified remote
(trusted) certificate where the directory server uses LDAP.
ip
: Type the IP address (in dotted decimal notation) or
the domain name of the directory server. The domain
name can use alphanumeric characters, periods and
hyphens. Up to 255 characters.
port
: Specify the LDAP server port number. You must use
the same server port number that the directory server
uses. 389 is the default server port number for LDAP.
The ZyWALL / USG may need to authenticate itself in
order to access the CRL directory server. Type the login
name (up to 31 characters) from the entity maintaining
the server (usually a certification authority). You can use
alphanumeric characters, the underscore and the dash.
Type the password (up to 31 characters) from the entity
maintaining the CRL directory server (usually a
certification authority). You can use the following
characters: a-zA-Z0-9;|`~!@#$%^&*()_+\{}':,./<>=-
ocsp {activate|deactivate}
Has the ZyWALL / USG check (or not check) incoming
certificates that are signed by this certificate against a
directory server that uses OCSP (Online Certificate Status
Protocol).
ocsp url
url
[id
name
password
password
]
[deactivate]
Sets the validation configuration for the specified remote
(trusted) certificate where the directory server uses OCSP.
url
: Type the protocol, IP address and pathname of the
OCSP server.
name: The ZyWALL / USG may need to authenticate itself
in order to access the OCSP server. Type the login name
(up to 31 characters) from the entity maintaining the
server (usually a certification authority). You can use
alphanumeric characters, the underscore and the dash.
password: Type the password (up to 31 characters) from
the entity maintaining the OCSP server (usually a
certification authority). You can use the following
characters: a-zA-Z0-9;|`~!@#$%^&*()_+\{}':,./<>=-
no ca category {local|remote}
certificate_name
Deletes the specified local (my certificates) or remote
(trusted certificates) certificate.
no ca validation
name
Removes the validation configuration for the specified
remote (trusted) certificate.
show ca category {local|remote} name
certificate_name
certpath
Displays the certification path of the specified local (my
certificates) or remote (trusted certificates) certificate.
Table 184
ca Commands Summary (continued)
COMMAND
DESCRIPTION
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...