Chapter 8 Certificates CommandsThe following section lists the certificates commands.Table 24 Certificates Commands

COMMAND

DESCRIPTION

M

certificates ca_trusted

Specifies whether or not the specified CA issues a CRL.

R+B

crl_issuer <name> [onoff]

onoff: specifies whether or not the CA issues CRL. If

 

 

[onoff] is not specified, the current CRL issuer status of the

 

 

CA displays.

 

certificates ca_trusted delete

Removes the specified trusted CA certificate.

R+B

<name>

 

 

certificates ca_trusted export

Exports the specified PEM-encoded certificate to your CLI

R+B

<name>

session’s window for you to copy and paste.

 

certificates ca_trusted

Imports the specified certificate file from the specified remote web

R+B

http_import <url> <name>

server as a trusted CA. The certificate file must be in one of the

 

[proxyurl]

following formats: 1) Binary X.509, 2) PEM-encoded X.509, 3)

 

 

Binary PKCS#7, and 4) PEM-encoded PKCS#7.

 

certificates ca_trusted import

Imports the specified PEM-encoded CA certificate from your CLI

R+B

<name>

session. After you enter the command, copy and paste the PEM-

 

 

encoded certificate into your CLI session window. With some

 

 

terminal emulation software you may need to move your mouse

 

 

around to get the transfer going.

 

 

 

 

certificates ca_trusted list

Displays all trusted CA certificate names and their basic

R+B

 

information.

 

certificates ca_trusted rename

Renames the specified trusted CA certificate.

R+B

<old-name><new-name>

 

 

certificates ca_trusted verify

Has the ZyWALL verify the certification path of the specified

R+B

<name> [timeout]

trusted CA certificate.

 

certificates ca_trusted view

Displays details about the specified trusted CA certificate.

R+B

<name>

 

 

certificates cert_manager

Re-initializes the certificate manager.

R+B

reinit

 

 

certificates dir_service add

Adds a new directory server entry.

R+B

<server-name> <ip-

 

 

address[:port]> [login:pswd]

 

 

certificates dir_service

Removes the specified directory server entry.

R+B

delete <server-name>

 

 

certificates dir_service edit

Edits the specified directory server entry.

R+B

<server-name> <ip-

 

 

address[:port]> [login:pswd]

 

 

certificates dir_service list

Displays all directory server entry names and their basic

R+B

 

information.

 

certificates dir_service

Renames the specified directory server entry.

R+B

rename <old-server-name> <new-

 

 

server-name>

 

 

certificates dir_service view

Displays details about the specified directory server entry.

R+B

<server-name>

 

 

certificates my_cert create

Creates a certificate request and enrolls for a certificate

R+B

scep_enroll <name> <ca-

immediately online using SCEP protocol.

 

address> <ca-cert><ra-sign>

ra-sign: specifies the name of the RA (Registration Authority)

 

<ra-encr> <auth key> <subject>

signing certificate. If it is not required, type ““ to leave it blank.

 

[key length]

ra-encr: specifies the name of the RA encryption certificate. If it

 

 

is not required, type ““ to leave it blank .

 

56

 

ZyWALL (ZyNOS) CLI Reference Guide