HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 182

PKI configuration commands, attribute

Page 182 highlights

PKI configuration commands attribute Syntax attribute id { alt-subject-name { fqdn | ip } | { issuer-name | subject-name } { dn | fqdn | ip } } { ctn | equ | nctn | nequ } attribute-value View undo attribute { id | all } Certificate attribute group view Default level 2: System level Parameters id: Sequence number of the certificate attribute rule, in the range of 1 to 16. alt-subject-name: Specifies the name of the alternative certificate subject. fqdn: Specifies the FQDN of the entity. ip: Specifies the IP address of the entity. issuer-name: Specifies the name of the certificate issuer. subject-name: Specifies the name of the certificate subject. dn: Specifies the distinguished name of the entity. ctn: Specifies the contain operation. equ: Specifies the equal operation. nctn: Specifies the not-contain operation. nequ: Specifies the not-equal operation. attribute-value: Value of the certificate attribute, a case-insensitive string of 1 to 128 characters. all: Specifies all certificate attributes. Description Use attribute to configure the attribute rules of the certificate issuer name, certificate subject name and alternative certificate subject name. Use undo attribute to delete the attribute rules of certificates. By default, no restriction exists on the issuer name, subject name, and alternative subject name of a certificate. The attribute of the alternative certificate subject name does not appear as a distinguished name, and therefore the dn keyword is not available for the attribute. Examples # Create a certificate attribute rule, specifying that the DN in the subject name includes the string of abc. 173

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

173
PKI configuration commands
attribute
Syntax
attribute
id
{
alt-subject-name
{
fqdn
|
ip
} | {
issuer-name
|
subject-name
} {
dn
|
fqdn
|
ip
} } {
ctn
|
equ
|
nctn
|
nequ
}
attribute-value
undo attribute
{
id
|
all
}
View
Certificate attribute group view
Default level
2: System level
Parameters
id
: Sequence number of the certificate attribute rule, in the range of 1 to 16.
alt-subject-name
: Specifies the name of the alternative certificate subject.
fqdn
: Specifies the FQDN of the entity.
ip
: Specifies the IP address of the entity.
issuer-name
: Specifies the name of the certificate issuer.
subject-name
: Specifies the name of the certificate subject.
dn
: Specifies the distinguished name of the entity.
ctn
: Specifies the contain operation.
equ
: Specifies the equal operation.
nctn
: Specifies the not-contain operation.
nequ
: Specifies the not-equal operation.
attribute-value
: Value of the certificate attribute, a case-insensitive string of 1 to 128 characters.
all
: Specifies all certificate attributes.
Description
Use
attribute
to configure the attribute rules of the certificate issuer name, certificate subject name and
alternative certificate subject name.
Use
undo attribute
to delete the attribute rules of certificates.
By default, no restriction exists on the issuer name, subject name, and alternative subject name of a
certificate.
The attribute of the alternative certificate subject name does not appear as a distinguished name, and
therefore the
dn
keyword is not available for the attribute.
Examples
# Create a certificate attribute rule, specifying that the DN in the subject name includes the string of
abc
.