R3166-R3206-HP High-End Firewalls VPN Command Reference-6PW101
117
A certificate attribute group must exist to be associated with a rule.
Examples
# Create an access control rule, specifying that a certificate is considered valid when it matches an
attribute rule in certificate attribute group mygroup.
<Sysname> system-view
[Sysname] pki certificate access-control-policy mypolicy
[Sysname-pki-cert-acp-mypolicy] rule 1 permit mygroup
state
Syntax
state state-name
undo state
View
PKI entity view
Default level
2: System level
Parameters
state-name: State or province name, a case-insensitive string of 1 to 31 characters. No comma can be
included.
Description
Use the state command to specify the name of the state or province where an entity resides.
Use the undo state command to remove the configuration.
By default, no state or province is specified.
Examples
# Specify the state where an entity resides.
<Sysname> system-view
[Sysname] pki entity 1
[Sysname-pki-entity-1] state country