pki whitelist filter enable

Function

The pki whitelist filter enable command enables the suffix filtering function to filter suffixes of whitelists imported into the device and common name suffixes of the certificates received from the peer end during whitelist-based IPsec certificate negotiation.

The undo pki whitelist filter enable command disables the suffix filtering function.

By default, the suffix filtering function is not enabled.

Format

pki whitelist filter enable

undo pki whitelist filter enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
pki write

Usage Guidelines

Usage Scenario

In whitelist-based IPsec certificate authentication scenarios, when the names of whitelists imported into a device or common names of the certificates received from the peer end are redundant, run the pki whitelist filter enable command to simplify the imported whitelists. For example, after the common name of a base station certificate on the live network is imported into a whitelist, a record carrying different suffixes may be generated, causing one base station in the whitelist to consume multiple whitelist resources. To resolve this problem, run the pki whitelist filter enable command.

Example

# Enable the suffix filtering function.
<HUAWEI> system-view
[~HUAWEI] pki whitelist filter enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >