HP 3600 v2 Series Security Configuration Manual page 269

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Figure 98 Configure a certificate attribute-based access control policy
Configuration procedure
NOTE:
For more information about SSL configuration, see the chapter "SSL configuration."
For more information about HTTPS configuration, see
The PKI domain to be referenced by the SSL policy must be created in advance. For how to configure a
PKI domain, see
Configure the HTTPS server
1.
# Configure the SSL policy for the HTTPS server to use.
<Device> system-view
[Device] ssl server-policy myssl
[Device-ssl-server-policy-myssl] pki-domain 1
[Device-ssl-server-policy-myssl] client-verify enable
[Device-ssl-server-policy-myssl] quit
Configure the certificate attribute group
2.
# Create certificate attribute group mygroup1 and add two attribute rules. The first rule defines that the
DN of the subject name includes the string aabbcc, and the second rule defines that the IP address of the
certificate issuer is 10.0.0.1.
[Device] pki certificate attribute-group mygroup1
[Device-pki-cert-attribute-group-mygroup1] attribute 1 subject-name dn ctn aabbcc
[Device-pki-cert-attribute-group-mygroup1] attribute 2 issuer-name ip equ 10.0.0.1
[Device-pki-cert-attribute-group-mygroup1] quit
# Create certificate attribute group mygroup2 and add two attribute rules. The first rule defines that the
FQDN of the alternative subject name does not include the string of apple, and the second rule defines
that the DN of the certificate issuer name includes the string aabbcc.
[Device] pki certificate attribute-group mygroup2
[Device-pki-cert-attribute-group-mygroup2] attribute 1 alt-subject-name fqdn nctn apple
[Device-pki-cert-attribute-group-mygroup2] attribute 2 issuer-name dn ctn aabbcc
[Device-pki-cert-attribute-group-mygroup2] quit
Configure the certificate attribute-based access control policy
3.
# Create the certificate attribute-based access control policy of myacp and add two access control rules.
[Device] pki certificate access-control-policy myacp
[Device-pki-cert-acp-myacp] rule 1 deny mygroup1
[Device-pki-cert-acp-myacp] rule 2 permit mygroup2
"Configure the PKI
domain."
Fundamentals Configuration Guide
258
.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents