Networking diagram
Figure 535 Diagram for configuring a certificate attribute-based access control policy
Host
HTTPS client
Configuration procedure
n
For detailed information about SSL configuration, refer to
■
on page
1953.
For detailed information about HTTPS configuration, refer to HTTP Server
■
Configuration in System Volume.
The PKI domain to be referenced by the SSL policy must be created in advance.
■
For detailed configuration of the PKI domain, refer to
Domain" on page
1 Configure the HTTPS server
# Configure the SSL policy for the HTTPS server to use.
<Router> system-view
[Router] ssl server-policy myssl
[Router-ssl-server-policy-myssl] pki-domain 1
[Router-ssl-server-policy-myssl] client-verify enable
[Router-ssl-server-policy-myssl] quit
2 Configure the certificate attribute group
# Create certificate attribute group mygroup1 and add two attribute rules. The
first rule defines that the DN of the subject name includes the string aabbcc, and
the second rule defines that the IP address of the certificate issuer is 10.0.0.1.
[Router] pki certificate attribute-group mygroup1
[Router-pki-cert-attribute-group-mygroup1] attribute 1 subject-name
dn ctn aabbcc
[Router-pki-cert-attribute-group-mygroup1] attribute 2 issuer-name i
p equ 10.0.0.1
[Router-pki-cert-attribute-group-mygroup1] quit
# Create certificate attribute group mygroup2 and add two attribute rules. The
first rule defines that the FQDN of the alternative subject name does not include
the string of apple, and the second rule defines that the DN of the certificate
issuer name includes the string aabbcc.
[Router] pki certificate attribute-group mygroup2
[Router-pki-cert-attribute-group-mygroup2] attribute 1 alt-subject-n
ame fqdn nctn apple
[Router-pki-cert-attribute-group-mygroup2] attribute 2 issuer-name d
IP network
1833.
PKI Configuration Examples
CA server
Router
HTTPS server
"SSL Configuration"
"Configuring a PKI
1847
Need help?
Do you have a question about the MSR 50 Series and is the answer not in the manual?