Certificate Domain - H3C MSR 20-20 Command Reference Manual

Msr 20/30/50 series routers
Hide thumbs Also See for MSR 20-20:
Table of Contents

Advertisement

2154
C
141: IKE C
HAPTER
Description
Related command:
Example

certificate domain

Syntax
View
Parameter
Description
Related command:
Example
dh
Syntax
View
Parameter
C
ONFIGURATION
OMMANDS
Use the
authentication-method
method to be used by an IKE proposal.
Use the
undo authentication-method
By default, an IKE proposal uses the pre-shared key authentication method.
ike proposal, display ike proposal.
# Specify that IKE proposal 10 uses the pre-shared key authentication method.
<Sysname> system-view
[Sysname] ike proposal 10
[Sysname-ike-proposal-10] authentication-method pre-share
certificate domain domain-name
undo certificate domain
IKE Peer view
domain-name: Name of the PKI domain, a string of 1 to 15 characters.
Use the
certificate domain
certificate when IKE uses digital signature as the authentication mode.
Use the
undo certificate domain
authentication-method on page 1721 and pki domain on page 2058.
# Configure the PKI domain as abcde for IKE negotiation.
<Sysname> system-view
[Sysname] ike peer peer
[Sysname-ike-peer-peer] certificate domain abcde
dh { group1 | group2 | group5 | group14 }
undo dh
IKE proposal view
group1: Uses the 768-bit Diffie-Hellman group for key negotiation in phase 1.
group2: Uses the 1024-bit Diffie-Hellman group for key negotiation in phase 1.
command to specify the authentication
command to restore the default.
command to configure the PKI domain of the
command to remove the configuration.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr 20-21Msr 30-16Msr 30-20Msr 30-40Msr 30-60Msr 50 ... Show all

Table of Contents