Zyxel USG 1900 [314/438] Configure termina

Zyxel USG 1900 [314/438] Configure termina
Chapter 48 Certificates
ZyWALL / USG (ZLD) CLI Reference Guide
314
48.4 Certificates Commands Summary
The following table lists the commands that you can use to display and manage the ZyWALL / USG’s
summary list of certificates and certification requests. You can also create certificates or
certification requests. Use the
configure terminal command to enter the configuration mode to
be able to use these commands.
organization Identify the company or group to which the certificate owner belongs. You can use
up to 31 characters. You can use alphanumeric characters, the hyphen and the
underscore.
country Identify the nation where the certificate owner is located. You can use up to 31
characters. You can use alphanumeric characters, the hyphen and the underscore.
key_length Type a number to determine how many bits the key should use (512, 768, 1024,
1536, 2048, 4096). The longer the key, the more secure it is. A longer key also uses
more PKI storage space.
password When you have the ZyWALL / USG enroll for a certificate immediately online, the
certification authority may want you to include a key (password) to identify your
certification request. Use up to 31 of the following characters. a-zA-Z0-
9;|`~!@#$%^&*()_+\{}':,./<>=-
ca_name When you have the ZyWALL / USG enroll for a certificate immediately online, you
must have the certification authority’s certificate already imported as a trusted
certificate. Specify the name of the certification authority’s certificate. It can be up
to 31 alphanumeric and ;‘~!@#$%^&()_+[]{}’,.=-
characters.
url When you have the ZyWALL / USG enroll for a certificate immediately online, enter
the IP address (or URL) of the certification authority server. You can use up to 511 of
the following characters. a-zA-Z0-9'()+,/:.=?;!*#@$_%-
ipv4 Enter an IPv4 address.
ipv6 Enter an IPv6 address.
Table 185 Certificates Commands Input Values (continued)
LABEL DESCRIPTION
Table 186 ca Commands Summary
COMMAND DESCRIPTION
ca generate pkcs10 name certificate_name cn-type {ip
cn ipv4 | ipv6 cn ipv6 |fqdn cn cn_domain_name|mail
cn cn_email} [ou organizational_unit] [o
organization] [c country] key-type {rsa|dsa|rsa-
sha256|rsa-sha512|dsa-sha256} key-len key_length
Generates a PKCS#10 certification request.
ca generate pkcs12 name name password password Generates a PKCS#12 certificate.
ca generate x509 name certificate_name cn-type {ip cn
ipv4 | ipv6 cn ipv6 | fqdn cn cn_domain_name | mail cn
cn_email} [ou organizational_unit] [o organization]
[c country] key-type {rsa|dsa|rsa-sha256|rsa-
sha512|dsa-sha256} key-len key_length
Generates a self-signed x509 certificate.
ca rename category {local|remote} old_name new_name Renames a local (my certificates) or remote (trusted
certificates) certificate.
ca validation remote_certificate Enters the sub command mode for validation of
certificates signed by the specified remote (trusted)
certificates.

Содержание

Похожие устройства

Скачать