8

Certificates Commands

Use these commands to configure certificates.

8.1 Command Summary

The following table describes the values required for many certificates commands. Other values are discussed with the corresponding commands.

Table 23 Certificates Commands Input Values

LABEL

DESCRIPTION

auth-key

Specifies the certificate’s key for user authentication. If the key contains spaces,

 

put it in quotes. To leave it blank, type "".

 

 

ca-address

The IP address or domain name of the CA (Certification Authority) server.

 

 

ca-cert

The name of the CA certificate.

 

 

ip-

Specifies the server address (required) and port (optional). The format is "server-

address[:port

address[:port]". The default port is 389.

]

 

key-length

The length of the key to use in creating a certificate or certificate request. Valid

 

options are 512, 768, 1024, 1536 and 2048 bits.

 

 

login:pswd

The login name and password for the directory server, if required. The format is

 

"login:password".

name

The identifying name of a certificate or certification request. Use up to 31

 

characters to identify a certificate. You may use any character (not including

 

spaces).

 

 

proxyurl

The address and port of an optional HTTP proxy to use.

 

 

server-name

A descriptive name for a directory server. Use up to 31 ASCII characters (spaces

 

are not permitted).

 

 

subject

A certificate’s subject name and alternative name. Both are required.

 

The format is "subject-name-dn;{ip,dns,email}=value".

 

Example 1: "CN=ZyWALL,OU=CPE SW2,O=ZyXEL,C=TW;ip=172.21.177.79"

 

Example 2: "CN=ZyWALL,O=ZyXEL,C=TW;dns=www.zyxel.com"

 

Example 3: "CN=ZyWALL,O=ZyXEL,C=TW;email=dummy@zyxel.com.tw"

 

If the name contains spaces, put it in quotes.

 

 

timeout

The verification timeout value in seconds (optional). The default timeout value is

 

20 seconds.

 

 

url

The location of a certificate to be imported.

 

 

 

55

ZyWALL (ZyNOS) CLI Reference Guide