The ssh user cert-verify-san enable command enables SAN/CN verification.
By default, the system does not check whether the common name (CN) or subject alternative name (SAN) in the certificate contains the domain name of the authenticated user.
ssh user user-name cert-verify-san enable
undo ssh user user-name cert-verify-san enable
Indicates the name of an SSH user.
The value is a string of 1 to 253 case-sensitive characters, spaces not supported.
System view
3: Management level
Usage Scenario
To ensure security, the common name (CN) or subject alternative name (SAN) in the certificate is verified.
Prerequisites
Specifies a PKI domain name for an SSH user.
<HUAWEI> system-view [~HUAWEI] ssh user aa cert-verify-san enable