< Home

flow-probe metadata-collect ca-certificate

Function

The flow-probe metadata-collect ca-certificate command specifies the CA certificate for authenticating the HiSec Insight server.

The undo flow-probe metadata-collect ca-certificate command is used to delete a specified CA certificate.

Format

flow-probe metadata-collect ca-certificate certificate-name

undo flow-probe metadata-collect ca-certificate

Parameters

Parameter Description Value

certificate-name

Specifies the name of the CA certificate used to authenticate the HiSec Insight server. The certificate size cannot exceed 10 KB and must be a certificate that has been imported to the device.

The value is a case-insensitive string of 1 to 64 characters.

Views

System view

Default Level

3: Management level

Usage Guidelines

By default, the CA certificate issued by Huawei is used to authenticate the HiSec Insight server certificate.

When sending information in metadata format to the HiSec Insight through SSL, you need to use the CA certificate issued by the CA server to perform unidirectional CA certificate authentication on the HiSec Insight server certificate. You can run the flow-probe metadata-collect ca-certificate command to specify the CA certificate for authenticating the HiSec Insight server.

Example

# Set the name of the CA certificate for authenticating the HiSec Insight server to ca.cer.

<sysname> system-view
[sysname] flow-probe metadata-collect ca-certificate ca.cer
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >