HP VPN Firewall Appliances VPN Command Reference

145
group-name: Name of the certificate attribute group to be associated with the rule, a case-insensitive
string of 1 to 16 characters. It cannot be "a", "al", or "all".
all: Specifies all access control rules.
Usage guidelines
A certificate attribute group must exist to be associated with a rule.
Examples
# Create an access control rule, specifying that a certificate is considered valid when it matches an
attribute rule in the certificate attribute group mygroup.
<Sysname> system-view
[Sysname] pki certificate access-control-policy mypolicy
[Sysname-pki-cert-acp-mypolicy] rule 1 permit mygroup
state
Use state to specify the name of the state or province where an entity resides.
Use undo state to remove the configuration.
Syntax
state state-name
undo state
Default
No state or province is specified.
Views
PKI entity view
Default command level
2: System level
Parameters
state-name: State or province name, a case-insensitive string of 1 to 31 characters. No comma can be
included.
Examples
# Specify the state where an entity resides.
<Sysname> system-view
[Sysname] pki entity 1
[Sysname-pki-entity-1] state country