externalCsrPki Show🔗
Toolbar🔗
Name |
Tooltip |
Description |
|---|---|---|
Preview |
PKI preview |
Fields🔗
Name |
Data type |
Description |
|---|---|---|
Created by |
string |
Administrator who created this PKI configuration. Displays the name or identifier of the administrator who created the object. Automatically populated for tracking and auditing purposes. |
Updated by |
string |
Administrator who last modified this PKI configuration. Indicates the name or identifier of the administrator who last modified the object. Used to track changes and maintain audit history. |
Name |
string |
Name of the PKI configuration. Specifies the name of the object. This field is required and should uniquely identify the object within its context. |
CA |
oneOf CaView |
Certificate Authority certificate details. |
Description |
string |
Description of this PKI configuration. Provides an optional text description of the object. Useful for documenting purpose, context, or configuration notes. |
Digest algorithm |
enum SHA1, SHA256, SHA384, SHA512, SHA3-256, SHA3-384, SHA3-512 |
Algorithm used for certificate signing (e.g., SHA-256, SHA-384). |
EAP default schema |
enum MD5, PEAP, TLS, GTC, MSCHAPv2 |
Default EAP authentication schema for this PKI. |
EAP MTU |
number |
Maximum Transmission Unit size for EAP communications. |
Check username |
boolean |
Whether username verification is enabled during authentication. |
Default |
boolean |
Whether this is the default PKI configuration in the system. |
Enabled |
boolean |
Whether this PKI configuration is enabled. Indicates whether the object is active or enabled. When disabled, the object becomes inactive or unavailable for use in operations. |
Notify when failed to download |
boolean |
Whether notifications are sent when certificate download fails. |
OSCP |
boolean |
Whether OCSP (Online Certificate Status Protocol) is enabled. |
OSCP override cert. URL |
boolean |
Whether to override the certificate’s OCSP URL with configured URL. |
OSCP soft fail |
boolean |
Whether OCSP soft fail mode is enabled (treats unreachable OCSP as valid). |
OSCP use non CE |
boolean |
Whether to use nonce in OCSP requests for added security. |
SCEP |
boolean |
Whether SCEP (Simple Certificate Enrollment Protocol) is enabled. |
SCEP URL |
string |
URL of the SCEP server for certificate enrollment. |
CRL distribution points |
string |
Locations where Certificate Revocation Lists can be obtained. |
Uploaded key |
boolean |
Whether the private key has been uploaded. |
Uploaded server |
boolean |
Whether the server certificate has been uploaded. |
Valid key |
boolean |
Whether the private key is valid. |
Valid server |
boolean |
Whether the server certificate is valid. |
WWW management |
boolean |
Whether web management interface is available for this PKI. |
RadSec enabled |
boolean |
Whether RadSec (RADIUS over TLS) is enabled for secure RADIUS. |
OSCP timeout |
number |
Timeout duration for OCSP responses in seconds. |
OSCP URL |
string |
URL of the OCSP responder for certificate validation. |
Server CA |
oneOf ServerCaView |
Server Certificate Authority configuration. |
TEAP primary schema |
enum NONE, PEAP, TLS |
Primary TEAP (Tunnel Extensible Authentication Protocol) schema. |
TEAP secondary schema |
enum NONE, PEAP, TLS |
Secondary TEAP schema for additional authentication methods. |
TLS max version |
enum 1.0, 1.1, 1.2, 1.3 |
Maximum TLS version supported for secure communications. |
TLS min version |
enum 1.0, 1.1, 1.2, 1.3 |
Minimum TLS version supported for secure communications. |
Panels🔗
Name |
Data type |
Template |
Description |
|---|---|---|---|
Administration groups |
array of entity preview |
Unordered list / Table |
Administration groups that can manage this PKI configuration. |
Cert. chain |
array of entity preview |
Unordered list / Table |
The certificate chain for this PKI configuration. |
SCEP certs |
array of |
Unordered list / Table |
SCEP certificates associated with this PKI. |