< Home

pki certificate attribute-group

Function

The pki certificate attribute-group command creates a certificate attribute group and displays the certificate attribute group view, or displays the view of an existing certificate attribute group.

The undo pki certificate attribute-group command deletes a certificate attribute group.

By default, no certificate attribute group is created.

Format

pki certificate attribute-group group-name

undo pki certificate attribute-group group-name

Parameters

Parameter Description Value
group-name Specifies the name of a certificate attribute group. The value is a string of 1 to 32 case-insensitive characters without spaces and question marks. If the character string is enclosed in double quotation marks, it can contain spaces and question marks.

Views

System view

Default Level

2: Configuration level

Usage Guidelines

A certificate attribute group contains the attribute rules of a certificate. To configure attribute rules, create a certificate attribute group first.

If multiple attribute rules are configured in a certificate attribute group, the relationship among the rules is AND. That is, the action defined in related certificate access control rule is taken only when the certificate to be verified matches all the rules.

Example

# Create the certificate attribute group group1 and enter the certificate attribute group view.

<sysname> system-view
[sysname] pki certificate attribute-group group1
[sysname-pki-attribute-group1]
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >