The flow-probe metadata-collect ca-certificate command specifies the CA certificate for authenticating the HiSec Insight server.
The undo flow-probe metadata-collect ca-certificate command is used to delete a specified CA certificate.
flow-probe metadata-collect ca-certificate certificate-name
undo flow-probe metadata-collect ca-certificate
| Parameter | Description | Value |
|---|---|---|
certificate-name |
Specifies the name of the CA certificate used to authenticate the HiSec Insight server. The certificate size cannot exceed 10 KB and must be a certificate that has been imported to the device. |
The value is a case-insensitive string of 1 to 64 characters. |
By default, the CA certificate issued by Huawei is used to authenticate the HiSec Insight server certificate.
When sending information in metadata format to the HiSec Insight through SSL, you need to use the CA certificate issued by the CA server to perform unidirectional CA certificate authentication on the HiSec Insight server certificate. You can run the flow-probe metadata-collect ca-certificate command to specify the CA certificate for authenticating the HiSec Insight server.