set validate-expiration

Last Updated : Dec 27, 2016 |

This command sets when a certificate's expiration date should be checked.

Syntax

set validate-expiration <never | initial-connection | always>

Parameters

Parameter

Description

Possible Values

Default Value

initial-connection

Verification of the server’s Identity certificate will be checked to ensure that the certificate date has not expired. This validation will be performed at the time of TLS connection establishment.

If auditing of the server’s Identity certificate reveals an expiration, a certificate exception alarm will be generated, but the H.248 TLS connection will remain connected.

initial-connection

always

Verification of the server’s Identity certificate will be checked to ensure that the certificate date has not expired. This validation will be performed at the time of TLS connection establishment.

Additionally, if auditing of the server’s Identity certificate reveals an expiration, a certificate exception alarm will be generated and the H.248 TLS connection will be released.

Active calls will persist for point-to-point connections. No new H.248 link registration will occur until the certificate has been replaced.

never

No verification of server certificate expiration will be performed at the time of TLS connection establishment.

If auditing of the server’s identity certificate reveals an expiration, a certificate exception alarm will be generated, but the H.248 TLS connection will remain connected.

User level

read-write

Context

certificate-options

Example

# set validate-expiration always

Validate Expiration     : always