Alcatel-Lucent 7450 System Management Manual page 158

Ethernet service switch
Hide thumbs Also See for 7450:
Table of Contents

Advertisement

Public Key Infrastructure (PKI) Commands
certificate-display-format
Syntax
certificate-display-format {ascii|utf8}
Context
config>system>security>pki
Description
This command specifies the display format used for the Certificates and Certificate Revocation Lists.
Default
ascii
Parameters
ascii — Specifies the ASCII format to use for the Certificates and Certificate Revocation Lists.
utf8 — Specifies the UTF8 format to use for the Certificates and Certificate Revocation Lists.
certificate-expiration-warning
Syntax
certificate-expiration-warning hours [repeat repeat-hours]
no certificate-expiration-warning
Context
config>system>security>pki
Description
With this command configured, the system will issues two types of warnings related to certificate
expiration:
This command specifies when system will issue BeforeExp message before a certificate expires. For
example, with certificate-expiration-warning 5, the system will issue a BeforeExp message 5
hours before a certificate expires. An optional repeat <repeat-hour> parameter will enable the sys-
tem to repeat the BeforeExp message every hour until the certificate expires.
If the user only wants AfterExp, then certificate-expiration-warning 0 can be used to achieve this.
BeforeExp and AfterExp warnings can be cleared in following cases:
Default
no certificate-expiration-warning
Page 158
• BeforeExp — A warning message issued before certificate expire
• AfterExp — A warning message issued when certificate expire
• The certificate is reloaded by the admin certificate reload command. In this case, if the
reloaded file is not expired, then AfterExp is cleared. And, if the reloaded file is outside of con-
figured warning window, then the BeforeExp is also cleared.
• When the ca-profile/ipsec-gw/ipsec-tunnel/cert-profile is shutdown, then BeforeExp and
AfterExp of corresponding certificates are cleared.
• When no certificate-expiration-warning command is configured, then all existing BeforeExp
and AfterExp are cleared.
• Users may change the configuration of the certificate-expiration-warning so that certain certif-
icates are no longer in the warning window. BeforeExp of corresponding certificates are cleared.
• If the system time changes so that the new time causes the certificates to no longer be in the
warning window, then BeforeExp is cleared. If the new time causes an expired certificate to
come non-expired, then AfterExp is cleared.
7450 ESS System Mangement Guide

Advertisement

Table of Contents
loading

Table of Contents