EasyManuals Logo

H3C S5120-EI Series User Manual

H3C S5120-EI Series
1166 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #784 background imageLoading...
Page #784 background image
1-20
Configuring a Certificate Attribute-Based Access Control Policy
Network requirements
z The client accesses the remote HTTP Security (HTTPS) server through the HTTPS protocol.
z SSL is configured to ensure that only legal clients log into the HTTPS server.
z Create a certificate attribute-based access control policy to control access to the HTTPS server.
Figure 1-4 Configure a certificate attribute-based access control policy
Configuration procedure
z For detailed information about SSL configuration, refer to SSL Configuration in the Security
Volume.
z For detailed information about HTTPS configuration, refer to HTTP Server Configuration in the
System Volume.
z The PKI domain to be referenced by the SSL policy must be created in advance. For detailed
configuration of the PKI domain, refer to
Configure the PKI domain.
1) Configure the HTTPS server
# Configure the SSL policy for the HTTPS server to use.
<Switch> system-view
[Switch] ssl server-policy myssl
[Switch-ssl-server-policy-myssl] pki-domain 1
[Switch-ssl-server-policy-myssl] client-verify enable
[Switch-ssl-server-policy-myssl] quit
2) Configure the certificate attribute group
# Create certificate attribute group mygroup1 and add two attribute rules. The first rule defines that the
DN of the subject name includes the string aabbcc, and the second rule defines that the IP address of
the certificate issuer is 10.0.0.1.
[Switch] pki certificate attribute-group mygroup1
[Switch-pki-cert-attribute-group-mygroup1] attribute 1 subject-name dn ctn aabbcc
[Switch-pki-cert-attribute-group-mygroup1] attribute 2 issuer-name ip equ 10.0.0.1
[Switch-pki-cert-attribute-group-mygroup1] quit

Table of Contents

Other manuals for H3C S5120-EI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the H3C S5120-EI Series and is the answer not in the manual?

H3C S5120-EI Series Specifications

General IconGeneral
BrandH3C
ModelS5120-EI Series
CategorySwitch
LanguageEnglish

Related product manuals