Shows the status of the policy settings of the Web UI, certificate authentication settings, and the certificate revocation settings.
Note
The Intelligent Virtual Execution - Server appliance does not have a Web UI.
For details about the policy settings of the Web UI for certificate authentication, user attributes for the X.509 certificate, and certificate revocation, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.
Note
This command is not currently used on the Intelligent Virtual Execution - Server compute node.
Syntax
show aaa authentication certificate
Parameters
None
Example
The following example shows the configuration settings for certificate authentication:
hostname # show aaa authentication certificate Certificate based authentication settings: Web Policy : allowed Certificate field for username : x509-cert-san-upn CA certificate bundle : client-cert-auth OCSP enabled : yes Default OCSP URL : Not Configured OCSP override responder : yes Basic constraints must present : yes No CRL file is configured.
Output fields
The following table describes the output fields for the show aaa authentication certificate command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Web Policy | Policy settings of the Web UI for certificate authentication to allow the user to choose one of the following options:
|
Certificate field for username | User attributes for the X.509 certificate that are used for certificate authentication. |
CA certificate bundle | Name of the certificate bundle. The bundle is always named |
OCSP enabled | Whether the Online Certificate Status Protocol (OCSP) is enabled or disabled so that the appliance can verify the status of the certificate revocation. |
Default OCSP URL | Whether the default URL is configured or not configured on the appliance. This URL is used when the appliance cannot communicate with the OCSP responder from the certificate. |
OCSP override responder | Whether the OCSP override responder is enabled or disabled so that the default OCSP responder is used when the certificate is being validated even if the certificate references an OCSP responder. |
Basic constraints must present | Whether the appliance allows or prohibits a certificate with a missing basic constraints extension. |
No CRL file is configured | Whether the CRL file is configured or not configured. Only one CRL file can be present on the system. |
User role
Admin
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9.1
Network Security: Release 7.9.1
Endpoint Security (HX): Release 2.5
Intelligent Virtual Execution - Server: Release 7.9.1
Email Security — Server: Release 7.9.0