The country command configures a country code for a PKI entity.
The undo country command deletes the country code of a PKI entity.
By default, no country code is configured for a PKI entity.
Parameter |
Description |
Value |
---|---|---|
country-code |
Specifies the country code of a PKI entity. |
A country code must be two-character long. If the entered country code contains lower case letters, the system automatically changes the lower case letters into upper case letters when you create a certificate request file. You can query country codes in ISO3166. For example, CN is the legitimate country code of China, and US is the legitimate country code of the USA. |
The parameters of a PKI entity contain the identity information of the entity. The CA identifies a certificate applicant based on identity information provided by the entity. To facilitate applicant identification, configure the country code for the PKI entity, which is used as an alias of the entity.
After the country code is configured for a PKI entity, the certificate request packet sent by the device to the CA server carries this country code. The CA server verifies every received certificate request packet. For each valid packet, the CA server generates a digital certificate carrying the country code of the PKI entity.