The certification user-cert-filter key-usage command configures whether only the client certificates that provide the digital signature function can be displayed in the certificate list.
| Parameter | Description | Value |
|---|---|---|
| any | Indicates the certificates that do not provide the digital signature function can still be displayed in the certificate list. | - |
| digital-signature | Indicates that only certificates that provide the digital signature function are displayed in the certificate list. | - |
By default, the certificates that do not provide the digital signature function can still be displayed in the certificate list.
If certificates are used for authentication and authorization, the user needs to select a certificate when logging in to the virtual gateway. If there are many certificates, you may have difficulties in selecting one. The administrator can filter out the certificates that do not meet the requirements by configuring whether only the client certificates that provide the digital signature function can be displayed in the certificate list, helping users to select certificates from the certificate list.
# Configuring whether only the client certificates that provide the digital signature function can be displayed in the certificate list.
<sysname> system-view [sysname] v-gateway gateway [sysname-gateway] security [sysname-gateway-security] certification user-cert-filter key-usage digital-signature