The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

aaa authentication certificate validation allow-missing-basic-constraints

Prev Next

Enables the appliance to allow the user to log in to the Web UI even when the basic constraints extension is not included in the X.509 certificate. The basic constraints extension is used to identify that the certificate is issued for a Certificate Authority (CA).

By default, the appliance verifies if the basic constraints extension is included in the X.509 certificate, and the login fails if the extension is not found.

For details about certificate revocation, refer to the "Configuring CAC for Certificate Authentication" appendix of the System Administration Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

[no] aaa authentication certificate validation allow-missing-basic-constraints

Parameters

no

Use the no form of this command to disable the option to allow the user to log in to the Web UI when the basic constraints extension is not included in the X.509 certificate.

Example

The following example shows how to enable the appliance to allow a certificate with a missing basic constraints extension.

hostname (config) # aaa authentication certificate validation allow-missing-basic-constraints

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Network Security: Release 7.9.1

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0