This command sets when a certificate's expiration date should be checked.
Syntax
set validate-expiration <never | initial-connection | always>
Parameters
Parameter
Description
Possible Values
Default Value
initial-connection
Verification of the server’s Identity certificate will be checked to ensure that the certificate date has not expired. This validation will be performed at the time of TLS connection establishment.
If auditing of the server’s Identity certificate reveals an expiration, a certificate exception alarm will be generated, but the H.248 TLS connection will remain connected.
initial-connection
always
Verification of the server’s Identity certificate will be checked to ensure that the certificate date has not expired. This validation will be performed at the time of TLS connection establishment.
Additionally, if auditing of the server’s Identity certificate reveals an expiration, a certificate exception alarm will be generated and the H.248 TLS connection will be released.
Active calls will persist for point-to-point connections. No new H.248 link registration will occur until the certificate has been replaced.
never
No verification of server certificate expiration will be performed at the time of TLS connection establishment.
If auditing of the server’s identity certificate reveals an expiration, a certificate exception alarm will be generated, but the H.248 TLS connection will remain connected.
User level
read-write
Context
certificate-options
Example
# set validate-expiration always
Validate Expiration : always