beautypg.com

Configuration procedure – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 299

background image

285

Figure 125 Network diagram

Configuration procedure

NOTE:

For more information about SSL configuration, see "Configuring SSL."

The PKI domain to be referenced by the SSL policy must be created in advance. For more information
about PKI domain configuration, see "Configure the PKI domain" in

Configure the AC

.

1.

Configure the HTTPS server

# Configure the SSL policy for the HTTPS server to use.

system-view

[AC] ssl server-policy myssl

[AC-ssl-server-policy-myssl] pki-domain 1

[AC-ssl-server-policy-myssl] client-verify enable

[AC-ssl-server-policy-myssl] quit

2.

Configure the certificate attribute group

# Create certificate attribute group mygroup1 and add two attribute rules. The first rule defines that the

DN of the subject name includes the string aabbcc, and the second rule defines that the IP address of the

certificate issuer is 10.0.0.1.

[AC] pki certificate attribute-group mygroup1

[AC-pki-cert-attribute-group-mygroup1] attribute 1 subject-name dn ctn aabbcc

[AC-pki-cert-attribute-group-mygroup1] attribute 2 issuer-name ip equ 10.0.0.1

[AC-pki-cert-attribute-group-mygroup1] quit

# Create certificate attribute group mygroup2 and add two attribute rules. The first rule defines that the
FQDN of the alternative subject name does not include the string of apple, and the second rule defines

that the DN of the certificate issuer name includes the string aabbcc.

[AC] pki certificate attribute-group mygroup2

[AC-pki-cert-attribute-group-mygroup2] attribute 1 alt-subject-name fqdn nctn apple

[AC-pki-cert-attribute-group-mygroup2] attribute 2 issuer-name dn ctn aabbcc

[AC-pki-cert-attribute-group-mygroup2] quit

3.

Configure the certificate attribute-based access control policy

# Create the certificate attribute-based access control policy of myacp and add two access control rules.

[AC] pki certificate access-control-policy myacp

[AC-pki-cert-acp-myacp] rule 1 deny mygroup1

[AC-pki-cert-acp-myacp] rule 2 permit mygroup2