show aaa authentication certificate

Prev Next

Shows the status of the policy settings of the Web UI, certificate authentication settings, and the certificate revocation settings.

Note

The Intelligent Virtual Execution - Server appliance does not have a Web UI.

For details about the policy settings of the Web UI for certificate authentication, user attributes for the X.509 certificate, and certificate revocation, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

show aaa authentication certificate

Parameters

None

Example

The following example shows the configuration settings for certificate authentication:

hostname # show aaa authentication certificate
        Certificate based authentication settings:
        Web Policy                     : allowed
        Certificate field for username : x509-cert-san-upn
        CA certificate bundle          : client-cert-auth
        OCSP enabled                   : yes
        Default OCSP URL               : Not Configured
        OCSP override responder        : yes
        Basic constraints must present : yes
        No CRL file is configured.
    

Output fields

The following table describes the output fields for the show aaa authentication certificate command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Web Policy

Policy settings of the Web UI for certificate authentication to allow the user to choose one of the following options:

  • allowed—Users log in to the Web UI either using the user name and password provided by their administrator or using an optional client X.509 certificate for user authentication.

  • required—Users log in to the Web UI using a certificate when a client X.509 certificate is mandatory for user authentication.

  • disabled—Policy settings of the Web UI are disabled and do not accept a certificate.

Certificate field for username

User attributes for the X.509 certificate that are used for certificate authentication.

CA certificate bundle

Name of the certificate bundle. The bundle is always named client-cert-auth.

OCSP enabled

Whether the Online Certificate Status Protocol (OCSP) is enabled or disabled so that the appliance can verify the status of the certificate revocation.

Default OCSP URL

Whether the default URL is configured or not configured on the appliance. This URL is used when the appliance cannot communicate with the OCSP responder from the certificate.

OCSP override responder

Whether the OCSP override responder is enabled or disabled so that the default OCSP responder is used when the certificate is being validated even if the certificate references an OCSP responder.

Basic constraints must present

Whether the appliance allows or prohibits a certificate with a missing basic constraints extension.

No CRL file is configured

Whether the CRL file is configured or not configured. Only one CRL file can be present on the system.

User role

Admin

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Network Security: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0