certificate update expire-time

Function

The certificate update expire-time command sets the automatic certificate update time, which is expressed in the percentage of the duration of a certificate in the validity period of the certificate.

The undo certificate update expire-time command restores the default setting.

By default, the automatic certificate update time is when the duration of a certificate of the validity period of the certificate reaches 50 percentage.

Format

certificate update expire-time valid-percent

undo certificate update expire-time

Parameters

Parameter Description Value
valid-percent

Specifies the percentage of a certificate's duration in the certificate's validity period.

The value is an integer ranging from 50 to 99. The default value is 50.

Views

PKI CMP session view, VS PKI CMP session view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
pki write

Usage Guidelines

Usage Scenario

A certificate authority (CA) specifies the validity period of a certificate before issuing the certificate. If a certificate has expired, the certificate cannot be used. You can run the certificate update expire-time command to set the time for updating certificates.

Prerequisites

Before you run the certificate update expire-time command, run the certificate auto-update enable command to enable the automatic certificate update function.

Configuration Impact

After you run the certificate update expire-time command on a device, the device automatically initiates a certificate update request to the connected CMPv2 server when the percentage of the duration of a certificate in the validity period of the certificate reaches a specified value.

Example

# Configure a device to trigger certificate update when the percentage of the duration of a certificate in the validity period of the certificate reaches 60%.
<HUAWEI> system-view
[~HUAWEI] pki domain domain1
[*HUAWEI-pki-domain-domain1] pki cmp session session1
[*HUAWEI-pki-domain-domain1-pki-cmp-session-session1] certificate update expire-time 60
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >