ssl verify-mode

Function

The ssl verify-mode command configures the DCN Secure Sockets Layer (SSL) authentication mode.

By default, the DCN SSL authentication mode is single.

Format

ssl verify-mode single

ssl verify-mode dual

undo ssl verify-mode

Parameters

Parameter Description Value
dual

Specifies the dual authentication mode.

-

single

Specifies the single authentication mode.

-

Views

DCN view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
dcn write

Usage Guidelines

Usage Scenario

In singe mode, SSL authentication is performed only on the GNE. In dual mode, SSL authentications are performed both on the GNE and NMS.

It is recommended that you configure the dual authentication mode to enhance system security.

Prerequisites

The DCN feature has been enabled globally using the dcn command in the system view.

The certificate of the SSL policy to be bound has been loaded to the NMSs and GNE using the certificate load command. The SSL policy has been configured using the ssl policy command.

Run the set compatible mode command to enable the DCN compatible mode

In VS mode, this command is supported only by the admin VS.

Example

# Configure the dual authentication mode.
<HUAWEI> system-view
[~HUAWEI] dcn
[*HUAWEI-dcn] set compatible mode
[*HUAWEI-dcn] ssl verify-mode dual
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >