logging <hostname-or-IP-address> tls certificate match-x509-cert-san-email <email-address>

Prev Next

For remote logging, add an explicit TLS X.509 certificate matching rule to match the remote syslog server by email address in the subjectAltName (SAN) field.

For strict compliance with the Common Criteria (CC-NDcPP) certification, syslog server certification verification for remote logging fails if the certificate is configured with an IP address instead of a hostname in the Common Name (CN) field. This command configures the certificate verification to match the email address in the subjAltName field.

To add multiple matching email addresses, configure a rule for each address separately.

Alternatively, you can add a rule to match the remote server by IP address using the logging <hostname-or-IP-address> tls certificate match-x509-cert-san-ipv4-or-ipv6 <IP address> command or by email address using the logging <hostname-or-IP-address> tls certificate match-x509-cert-san-or-cn-hostname <hostname> command

Syntax

[no] logging <hostname or IP address> tls certificate match-x509-cert-san-email <email-addr>

Parameters

<term>
no
</term>
Disable matching of the subjectAltName field of a certificate by the specified email address.<term>
hostname-or-IP-address
</term>
The hostname or IP address of the remote logging server.<term>
email-addr
</term>
The email address to match.

Example

The following example enables an explicit X.509 rule to match the subjectAltName field of a certificate by the specified email address.

hostname (config) # logging 192.0.2.1 tls certificate match-x509-cert-san-email your.name@example.com 

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 9.0.2.