Skip to main content
Version: current

certificate


certificate

Type: Directory

FlagNameDescription
Kprivate-keyprivate-key
Lcrlcrl
Csmart-card-keysmart-card-key
Aauthorityauthority
Iissuedissued
Rrevokedrevoked
Eexpiredexpired
Ttrustedtrusted
aacme-managedacme-managed
Ddynamicdynamic
ArgumentTypeDescription
activeswitch
inactiveswitch
namestring
trust-storealt { all: enum (all) , component: ubit (ipsec, wpa-eap, capsman, fetch, sstp, ovpn, mqtt, email, netwatch, radius, container, userman, lora, wiliot, openflow, tr069, dot1x, dns, www, api, reverse-proxy, logging) }
digest-algorithmenum (md5 | sha1 | sha256 | sha384 | sha512)
trustedbool
common-namestring
organizationstring
unitstring
localitystring
statestring
countrystring
subject-alt-nameobject { alt-name: composite { type: enum (IP | DNS | email) , value: alt { ip: alt { ipv6: ip6Addr , ip: ipAddr } , string: string } } }
key-sizeenum (prime256v1 | secp384r1 | secp521r1 | 1024 | 1536 | 2048 | 4096 | 8192) { 1024:1024, 1536:1536, 2048:2048, 4096:4096, 8192:8192 }
key-usageubit (digital-signature, content-commitment, key-encipherment, data-encipherment, key-agreement, key-cert-sign, crl-sign, encipher-only, decipher-only, tls-server, tls-client, code-sign, email-protect, timestamp, ocsp-sign, dvcs)
days-validnum
Read-only ArgumentTypeDescription
ca-crl-hoststring
caenum
scep-urlstring
fingerprintstring
req-fingerprintstring
ca-fingerprintstring
expires-aftertime
challenge-passwordstring
domain-namesstring
directory-urlstring
acme-statusstring
revokeddate
statusstring
issuermulti { array-id, issuer: string }
key-typeenum (rsa | dsa | ec)
invalid-beforedate
invalid-afterdate
serial-numberstring
akidstring
skidstring