EasyManuals Logo

H3C MSR Series Command Reference

H3C MSR Series
1187 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #518 background imageLoading...
Page #518 background image
495
Predefined user roles
network-admin
Parameters
domain-name: Specifies a PKI domain by its name, a case-insensitive string of 1 to 31 characters.
The domain name cannot contain the special characters listed in Table 74.
Table 74 Special characters
Character name
Symbol
Character name
Symbol
Tilde ~ Dot .
Asterisk * Left angle bracket <
Backslash \ Right angle bracket >
Vertical bar | Quotation marks "
Colon : Apostrophe '
Usage guidelines
CRLs are used to verify the validity of the local certificates and the peer certificates in a PKI domain.
To obtain CRLs, a PKI domain must have the correct CA certificate.
The URL of the CRL repository is specified by using the crl url command.
The device can obtain CRLs from the CRL repository through the HTTP, LDAP, or SCEP protocol.
Which protocol is used depends on the configuration of the CRL repository in the PKI domain:
If the specified URL of the CRL repository is in HTTP format, the device obtains CRLs through
the HTTP protocol.
If the specified URL of the CRL repository is in LDAP format, the device obtains CRLs through
the LDAP protocol. If the specified URL does not have a host name, for example,
ldap:///CN=8088,OU=test,U=rd,C=cn, you must specify the LDAP server's URL for the PKI
domain by using the ldap server command. The device can obtain the complete URL of the
LDAP repository by combining the URLs of the LDAP server and of the CRL repository.
If the PKI domain is not configured with the CRL repository, the device looks up the local
certificates and then the CA certificate for the CRL repository. If a CRL repository is found, the
device obtains CRLs from the CRL repository. If no CRL repository is found, the device obtains
CRLs through the SCEP protocol.
Examples
# Obtain CRLs from the CRL repository.
<Sysname> system-view
[Sysname] pki retrieve-crl domain aaa
Related commands
crl url
ldap server
pki storage
Use pki storage to specify the storage path for the certificates or CRLs.
Use undo pki storage to restore the default.
Syntax
pki storage { certificates | crls } dir-path

Table of Contents

Other manuals for H3C MSR Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the H3C MSR Series and is the answer not in the manual?

H3C MSR Series Specifications

General IconGeneral
CategoryNetwork Router
IPv6 SupportYes
DimensionsVaries by model
WeightVaries by model
Product TypeModular Router
PortsVaries by model
WAN InterfacesVaries by model
FirewallYes
QoSYes
Wireless SupportVaries by model
USB PortsVaries by model
Console PortYes
Power SupplyVaries by model
RedundancyVaries by model
Operating Temperature0°C to 45°C
Storage Temperature-40°C to 70°C
Humidity5% to 95% non-condensing
SeriesMSR
CertificationsCE, FCC, RoHS

Related product manuals