R3166-R3206-HP High-End Firewalls Network Management Command Reference-6PW101

Table Of Contents
497
Default level
2: System level
Parameters
None
Description
Use the client-verify enable command to enable certificate-based SSL client authentication, that is, to
enable the SSL server to perform certificate-based authentication of the client during the SSL handshake
process.
Use the undo client-verify enable command to restore the default.
By default, certificate-based SSL client authentication is disabled.
Related commands: display ssl server-policy.
Examples
# Enable certificate-based client authentication.
<Sysname> system-view
[Sysname] ssl server-policy policy1
[Sysname-ssl-server-policy-policy1] client-verify enable
close-mode wait
Syntax
close-mode wait
undo close-mode wait
View
SSL server policy view
Default level
2: System level
Parameters
None
Description
Use the close-mode wait command to set the SSL connection close mode to wait mode. In this mode,
after sending a close-notify alert message to a client, the server does not close the connection until it
receives a close-notify alert message from the client.
Use the undo close-mode wait command to restore the default.
By default, an SSL server sends a close-notify alert message to the client and closes the connection
without waiting for the close-notify alert message from the client.
Related commands: display ssl server-policy.
Examples
# Set the SSL connection close mode to wait mode.
<Sysname> system-view
[Sysname] ssl server-policy policy1