< Home

ocsp-url from-ca

Function

The ocsp-url from-ca command configures a PKI entity to obtain the OCSP server's URL from the Authority Info Access (AIA) option in a CA certificate.

The undo ocsp-url from-ca command disables a PKI entity from obtaining the OCSP server's URL from the AIA option in a CA certificate.

By default, a PKI entity does not obtain OCSP server's URL from a CA certificate's AIA option.

Only devices in NETCONF mode support this command.

Format

ocsp-url from-ca

undo ocsp-url from-ca

Parameters

None

Views

PKI realm view

Default Level

2: Configuration level

Usage Guidelines

If a certificate to be checked through OCSP contains the AIA option, run this command to configure the PKI entity to obtain OSCP server's URL from the AIA option. If the certificate does not contain the AIA option, run the ocsp url command to configure the OCSP server's URL.

Example

# Configure a PKI entity to obtain OCSP server's URL from a CA certificate's AIA option.

<HUAWEI> system-view
[HUAWEI] pki realm test
[HUAWEI-pki-realm-test] ocsp-url from-ca
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >