3Com Switch 4800G 24-Port Configuration Manual page 1234

Switch 4800g family 24-port, pwr 24-port, 48-port, pwr 48-port, 24-port sfp
Hide thumbs Also See for Switch 4800G 24-Port:
Table of Contents

Advertisement

1234
C
97: PKI C
HAPTER
ONFIGURATION
n
Networking diagram
Figure 362 Diagram for configuring a certificate attribute-based access control policy
Host
HTTPS client
Configuration procedure
For detailed information about SSL configuration, refer to "SSL Configuration"
on page 1207.
For detailed information about HTTPS configuration, refer to "HTTPS
Configuration" on page 1213.
The PKI domain to be referenced by the SSL policy must be created in advance.
For detailed configuration of the PKI domain, refer to "Configure the PKI
domain" on page 1231.
Configure the HTTPS server
# Configure the SSL policy for the HTTPS server to use.
<Switch> system-view
[Switch] ssl server-policy myssl
[Switch-ssl-server-policy-myssl] pki-domain 1
[Switch-ssl-server-policy-myssl] client-verify enable
[Switch-ssl-server-policy-myssl] quit
1 Configure the certificate attribute group
# Create certificate attribute group mygroup1 and add two attribute rules. The
first rule defines that the DN of the subject name includes the string aabbcc, and
the second rule defines that the IP address of the certificate issuer is 10.0.0.1.
[Switch] pki certificate attribute-group mygroup1
[Switch-pki-cert-attribute-group-mygroup1] attribute 1 subject-name
dn ctn aabbcc
[Switch-pki-cert-attribute-group-mygroup1] attribute 2 issuer-name i
p equ 10.0.0.1
[Switch-pki-cert-attribute-group-mygroup1] quit
# Create certificate attribute group mygroup2 and add two attribute rules. The
first rule defines that the FQDN of the alternative subject name does not include
the string of apple, and the second rule defines that the DN of the certificate
issuer name includes the string aabbcc.
[Switch] pki certificate attribute-group mygroup2
[Switch-pki-cert-attribute-group-mygroup2] attribute 1 alt-subject-name fqdn nctn apple
[Switch-pki-cert-attribute-group-mygroup2] attribute 2 issuer-name dn ctn aabbcc
[Switch-pki-cert-attribute-group-mygroup2] quit
IP network
CA server
Switch
HTTPS server

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents