Chapter 31 Certificates
ZyWALL (ZLD) CLI Reference Guide
269
ca generate pkcs10 name
certificate_name
cn-
type {ip cn
cn_address
|fqdn cn
cn_domain_name
|mail cn
cn_email
} [ou
organizational_unit
] [o
organization
] [c
country
] key-type {rsa|dsa} key-len
key_length
Generates a PKCS#10 certification request.
ca generate pkcs12 name
name
password
password
Generates a PKCS#12 certificate.
ca generate x509 name
certificate_name
cn-type
{ip cn
cn_address
|fqdn cn
cn_domain_name
cn
cn_email
} [ou
organizational_unit
] [o
organization
] [c
country
] key-type {rsa|dsa}
key-len
key_length
Generates a self-signed x509 certificate.
ca rename category {local|remote}
old_name
new_name
Renames a local (my certificates) or remote
(trusted certificates) certificate.
ca validation
remote_certificate
Enters the sub command mode for validation of
certificates signed by the specified remote (trusted)
certificates.
cdp {activate|deactivate}
Has the ZyWALL check (or not check) incoming
certificates that are signed by this certificate
against a Certificate Revocation List (CRL) or an
OCSP server. You also need to configure the
OSCP or LDAP server details.
ldap {activate|deactivate}
Has the ZyWALL check (or not check) incoming
certificates that are signed by this certificate
against a Certificate Revocation List (CRL) on a
LDAP (Lightweight Directory Access Protocol)
directory server.
ldap ip {
ip
|
fqdn
} port <1..65535> [id
name
password
password
] [deactivate]
Sets the validation configuration for the specified
remote (trusted) certificate where the directory
server uses LDAP.
ip
: Type the IP address (in dotted decimal
notation) or the domain name of the directory
server. The domain name can use alphanumeric
characters, periods and hyphens. Up to 255
characters.
port
: Specify the LDAP server port number. You
must use the same server port number that the
directory server uses. 389 is the default server port
number for LDAP.
The ZyWALL may need to authenticate itself in
order to access the CRL directory server. Type the
login name (up to 31 characters) from the entity
maintaining the server (usually a certification
authority). You can use alphanumeric characters,
the underscore and the dash.
Type the password (up to 31 characters) from the
entity maintaining the CRL directory server (usually
a certification authority). You can use the following
characters: a-zA-Z0-9;|`~!@#$%^&*()_+\{}':,./<>=-
ocsp {activate|deactivate}
Has the ZyWALL check (or not check) incoming
certificates that are signed by this certificate
against a directory server that uses OCSP (Online
Certificate Status Protocol).
Table 154
ca Commands Summary (continued)
COMMAND
DESCRIPTION
Summary of Contents for ZyWall
Page 2: ......
Page 6: ...Document Conventions ZyWALL ZLD CLI Reference Guide 6 ...
Page 10: ...10 ...
Page 26: ...Chapter 1 Command Line Interface ZyWALL ZLD CLI Reference Guide 26 ...
Page 46: ...46 ...
Page 84: ...Chapter 6 Interfaces ZyWALL ZLD CLI Reference Guide 84 ...
Page 98: ...Chapter 8 Route ZyWALL ZLD CLI Reference Guide 98 ...
Page 106: ...Chapter 10 Zones ZyWALL ZLD CLI Reference Guide 106 ...
Page 110: ...Chapter 11 DDNS ZyWALL ZLD CLI Reference Guide 110 ...
Page 116: ...Chapter 12 Virtual Servers ZyWALL ZLD CLI Reference Guide 116 ...
Page 120: ...Chapter 13 HTTP Redirect ZyWALL ZLD CLI Reference Guide 120 ...
Page 124: ...Chapter 14 ALG ZyWALL ZLD CLI Reference Guide 124 ...
Page 125: ...125 PART III Firewall Firewall 127 ...
Page 126: ...126 ...
Page 134: ...Chapter 15 Firewall ZyWALL ZLD CLI Reference Guide 134 ...
Page 135: ...135 PART IV VPN IPSec VPN 137 SSL VPN 147 L2TP VPN 153 ...
Page 136: ...136 ...
Page 146: ...Chapter 16 IPSec VPN ZyWALL ZLD CLI Reference Guide 146 ...
Page 152: ...Chapter 17 SSL VPN ZyWALL ZLD CLI Reference Guide 152 ...
Page 160: ...Chapter 18 L2TP VPN ZyWALL ZLD CLI Reference Guide 160 ...
Page 161: ...161 PART V Application Patrol Application Patrol 163 ...
Page 162: ...162 ...
Page 174: ...Chapter 19 Application Patrol ZyWALL ZLD CLI Reference Guide 174 ...
Page 175: ...175 PART VI Anti X Anti Virus 177 IDP Commands 185 Content Filtering 203 Anti Spam 215 ...
Page 176: ...176 ...
Page 202: ...Chapter 21 IDP Commands ZyWALL ZLD CLI Reference Guide 202 ...
Page 214: ...Chapter 22 Content Filtering ZyWALL ZLD CLI Reference Guide 214 ...
Page 224: ...Chapter 23 Anti Spam ZyWALL ZLD CLI Reference Guide 224 ...
Page 225: ...225 PART VII Device HA Device HA 227 ...
Page 226: ...226 ...
Page 236: ...236 ...
Page 248: ...Chapter 26 Addresses ZyWALL ZLD CLI Reference Guide 248 ...
Page 252: ...Chapter 27 Services ZyWALL ZLD CLI Reference Guide 252 ...
Page 262: ...Chapter 29 AAA Server ZyWALL ZLD CLI Reference Guide 262 ...
Page 266: ...Chapter 30 Authentication Objects ZyWALL ZLD CLI Reference Guide 266 ...
Page 272: ...Chapter 31 Certificates ZyWALL ZLD CLI Reference Guide 272 ...
Page 276: ...Chapter 32 ISP Accounts ZyWALL ZLD CLI Reference Guide 276 ...
Page 280: ...Chapter 33 SSL Application ZyWALL ZLD CLI Reference Guide 280 ...
Page 288: ...Chapter 34 Endpoint Security ZyWALL ZLD CLI Reference Guide 288 ...
Page 289: ...289 PART IX System System 291 System Remote Management 299 ...
Page 290: ...290 ...
Page 298: ...Chapter 35 System ZyWALL ZLD CLI Reference Guide 298 ...
Page 314: ...314 ...
Page 332: ...Chapter 37 File Manager ZyWALL ZLD CLI Reference Guide 332 Figure 55 Startup Complete ...
Page 344: ...Chapter 39 Reports and Reboot ZyWALL ZLD CLI Reference Guide 344 ...
Page 346: ...Chapter 40 Session Timeout ZyWALL ZLD CLI Reference Guide 346 ...
Page 348: ...Chapter 41 Diagnostics ZyWALL ZLD CLI Reference Guide 348 ...
Page 362: ...Chapter 44 Watchdog Timer ZyWALL ZLD CLI Reference Guide 362 ...
Page 363: ...363 PART XI Command List List of Commands Alphabetical 365 ...
Page 364: ...364 ...
Page 394: ...List of Commands Alphabetical ZyWALL ZLD CLI Reference Guide 394 ...