< Home

certification user-cert-filter key-usage

Function

The certification user-cert-filter key-usage command configures whether only the client certificates that provide the digital signature function can be displayed in the certificate list.

Format

certification user-cert-filter key-usage { any | digital-signature }

Parameters

Parameter Description Value
any Indicates the certificates that do not provide the digital signature function can still be displayed in the certificate list. -
digital-signature Indicates that only certificates that provide the digital signature function are displayed in the certificate list. -

Views

Security view

Default Level

2: Configuration level

Usage Guidelines

By default, the certificates that do not provide the digital signature function can still be displayed in the certificate list.

If certificates are used for authentication and authorization, the user needs to select a certificate when logging in to the virtual gateway. If there are many certificates, you may have difficulties in selecting one. The administrator can filter out the certificates that do not meet the requirements by configuring whether only the client certificates that provide the digital signature function can be displayed in the certificate list, helping users to select certificates from the certificate list.

Example

# Configuring whether only the client certificates that provide the digital signature function can be displayed in the certificate list.

<sysname> system-view
[sysname] v-gateway gateway
[sysname-gateway] security
[sysname-gateway-security] certification user-cert-filter key-usage digital-signature
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >