HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 228

The defaults are as follows, Specify a PKI domain for

Page 228 highlights

Step 3. Specify a PKI domain for the SSL server policy. 4. Specify the cipher suite(s) for the SSL server policy to support. 5. Set the handshake timeout time for the SSL server. 6. Set the SSL connection close mode. 7. Set the maximum number of cached sessions and the caching timeout time. 8. Enable the SSL server to perform digital certificate-based authentication for SSL clients. 9. Enable SSL client weak authentication. Command pki-domain domain-name ciphersuite [ rsa_3des_ede_cbc_sha | rsa_aes_128_cbc_sha | rsa_aes_256_cbc_sha | rsa_des_cbc_sha | rsa_rc4_128_md5 | rsa_rc4_128_sha ] * handshake timeout time close-mode wait session { cachesize size | timeout time } * client-verify enable client-verify weaken Remarks Optional. By default, no PKI domain is specified for an SSL server policy. The SSL server generates a certificate itself instead of requesting one from the CA. After you specify a PKI domain, the SSL server requests a certificate through the PKI domain. If the client requires certificate-based authentication for the SSL server, you must use this command to specify a PKI domain. For more information about PKI domain configuration, see "Configuring PKI." Optional. By default, an SSL server policy supports all cipher suites. Optional. 3,600 seconds by default. Optional. Not wait by default. Optional. The defaults are as follows: • 500 for the maximum number of cached sessions. • 3600 seconds for the caching timeout time. Optional. By default, the SSL server does not require clients to be authenticated. Optional. Disabled by default. This command takes effect only when the client-verify enable command is configured. 218

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

218
Step
Command
Remarks
3.
Specify a PKI domain for the
SSL server policy.
pki-domain
domain-name
Optional.
By default, no PKI domain is
specified for an SSL server policy.
The SSL server generates a
certificate itself instead of
requesting one from the CA.
After you specify a PKI domain, the
SSL server requests a certificate
through the PKI domain.
If the client requires
certificate-based authentication for
the SSL server, you must use this
command to specify a PKI domain.
For more information about PKI
domain configuration, see
"
Configuring PKI
."
4.
Specify the cipher suite(s) for
the SSL server policy to
support.
ciphersuite
[
rsa_3des_ede_cbc_sha
|
rsa_aes_128_cbc_sha
|
rsa_aes_256_cbc_sha
|
rsa_des_cbc_sha
|
rsa_rc4_128_md5
|
rsa_rc4_128_sha
]
*
Optional.
By default, an SSL server policy
supports all cipher suites.
5.
Set the handshake timeout
time for the SSL server.
handshake timeout
time
Optional.
3,600 seconds by default.
6.
Set the SSL connection close
mode.
close-mode wait
Optional.
Not wait by default.
7.
Set the maximum number of
cached sessions and the
caching timeout time.
session
{
cachesize
size
|
timeout
time
} *
Optional.
The defaults are as follows:
500 for the maximum number
of cached sessions.
3600 seconds for the caching
timeout time.
8.
Enable the SSL server to
perform digital
certificate-based
authentication for SSL clients.
client-verify enable
Optional.
By default, the SSL server does not
require clients to be authenticated.
9.
Enable SSL client weak
authentication.
client-verify weaken
Optional.
Disabled by default.
This command takes effect only
when the
client-verify enable
command is configured.