The set validate-alternate-name checks that the Subject Alternate Name field of the server’s end entity certificate matches the address of the TLS server, that is, Communication Manager.
Syntax
set validate-alternate-name [yes | no]
Parameters
Parameter
Description
Possible Values
Default Value
yes
The alternate-name field in the peer's certificate should be checked against the ip-address-map.
disabled
no
The alternate-name field in the peer's certificate should not be checked against the ip-address-map.
disabled
User level
read-write
Context
certificate-options
Example
# set validate-alternate-name yes
Validate Alternate Name : yes