Fortinet black logo

CLI Reference

config certificate setting

config certificate setting

Certificate setting.

config certificate setting
    Description: Certificate setting.
    set check-ca-cert [enable|disable]
    set subject-match [substring|value]
    set cn-match [substring|value]
    set strict-crl-check [enable|disable]
    set certname-rsa1024 {string}
    set certname-rsa2048 {string}
    set certname-dsa1024 {string}
    set certname-dsa2048 {string}
    set certname-ecdsa256 {string}
    set certname-ecdsa384 {string}
end

config certificate setting

Parameter

Description

Type

Size

check-ca-cert

Enable to check the CA certificate and fail authentication if certificate is not found.

option

-

Option

Description

enable

Enable checking the CA certificate.

disable

Disable checking the CA certificate.

subject-match

When searching for a matching certificate, control how to find matches in the certificate subject name.

option

-

Option

Description

substring

Find a match if any string in the certificate subject name matches the name being searched for.

value

Find a match if any attribute value string in a certificate subject name is an exact match with the name being searched for.

cn-match

When searching for a matching certificate, control how to find matches in the cn attribute of the certificate subject name.

option

-

Option

Description

substring

Find a match if any string in a certificate subject name cn attribute name matches the name being searched for.

value

Find a match if the cn attribute value string is an exact match with the name being searched for.

strict-crl-check

Enable/disable strict mode CRL checking.

option

-

Option

Description

enable

Enable strict mode CRL checking.

disable

Disable strict mode CRL checking.

certname-rsa1024

1024 bit RSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-rsa2048

2048 bit RSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-dsa1024

1024 bit DSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-dsa2048

2048 bit DSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-ecdsa256

256 bit ECDSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-ecdsa384

384 bit ECDSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

config certificate setting

Certificate setting.

config certificate setting
    Description: Certificate setting.
    set check-ca-cert [enable|disable]
    set subject-match [substring|value]
    set cn-match [substring|value]
    set strict-crl-check [enable|disable]
    set certname-rsa1024 {string}
    set certname-rsa2048 {string}
    set certname-dsa1024 {string}
    set certname-dsa2048 {string}
    set certname-ecdsa256 {string}
    set certname-ecdsa384 {string}
end

config certificate setting

Parameter

Description

Type

Size

check-ca-cert

Enable to check the CA certificate and fail authentication if certificate is not found.

option

-

Option

Description

enable

Enable checking the CA certificate.

disable

Disable checking the CA certificate.

subject-match

When searching for a matching certificate, control how to find matches in the certificate subject name.

option

-

Option

Description

substring

Find a match if any string in the certificate subject name matches the name being searched for.

value

Find a match if any attribute value string in a certificate subject name is an exact match with the name being searched for.

cn-match

When searching for a matching certificate, control how to find matches in the cn attribute of the certificate subject name.

option

-

Option

Description

substring

Find a match if any string in a certificate subject name cn attribute name matches the name being searched for.

value

Find a match if the cn attribute value string is an exact match with the name being searched for.

strict-crl-check

Enable/disable strict mode CRL checking.

option

-

Option

Description

enable

Enable strict mode CRL checking.

disable

Disable strict mode CRL checking.

certname-rsa1024

1024 bit RSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-rsa2048

2048 bit RSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-dsa1024

1024 bit DSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-dsa2048

2048 bit DSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-ecdsa256

256 bit ECDSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35

certname-ecdsa384

384 bit ECDSA key certificate for re-signing server certificates for SSL inspection.

string

Maximum length: 35