config vpn certificate hsm-local
Local certificates whose keys are stored on HSM.
config vpn certificate hsm-local
Description: Local certificates whose keys are stored on HSM.
edit <name>
set api-version [unknown|gch-default]
set certificate {user}
set comments {string}
set gch-cloud-service-name {string}
set gch-cryptokey {string}
set gch-cryptokey-algorithm [rsa-sign-pkcs1-2048-sha256|rsa-sign-pkcs1-3072-sha256|...]
set gch-cryptokey-version {string}
set gch-keyring {string}
set gch-location {string}
set gch-project {string}
set gch-url {string}
set range [global|vdom]
set source [factory|user|...]
set vendor [unknown|gch]
next
end
config vpn certificate hsm-local
|
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
api-version |
API version for communicating with HSM. |
option |
- |
unknown |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
certificate |
PEM format certificate. |
user |
Not Specified |
|
||||||||||||||||||||||||
|
comments |
Comment. |
string |
Maximum length: 511 |
|
||||||||||||||||||||||||
|
gch-cloud-service-name |
Cloud service config name to generate access token. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
gch-cryptokey |
Google Cloud HSM cryptokey. |
string |
Maximum length: 63 |
|
||||||||||||||||||||||||
|
gch-cryptokey-algorithm |
Google Cloud HSM cryptokey algorithm. |
option |
- |
rsa-sign-pkcs1-2048-sha256 |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
gch-cryptokey-version |
Google Cloud HSM cryptokey version. |
string |
Maximum length: 31 |
|
||||||||||||||||||||||||
|
gch-keyring |
Google Cloud HSM keyring. |
string |
Maximum length: 63 |
|
||||||||||||||||||||||||
|
gch-location |
Google Cloud HSM location. |
string |
Maximum length: 63 |
|
||||||||||||||||||||||||
|
gch-project |
Google Cloud HSM project ID. |
string |
Maximum length: 31 |
|
||||||||||||||||||||||||
|
gch-url |
Google Cloud HSM key URL (e.g. "https://cloudkms.googleapis.com/v1/projects/sampleproject/locations/samplelocation/keyRings/samplekeyring/cryptoKeys/sampleKeyName/cryptoKeyVersions/1"). Read-only. |
string |
Maximum length: 1024 |
|
||||||||||||||||||||||||
|
name |
Name. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
range |
Either a global or VDOM IP address range for the certificate. |
option |
- |
vdom |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
source |
Certificate source type. |
option |
- |
user |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
vendor |
HSM vendor. |
option |
- |
unknown |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||