D-Link DGS-3426 User Manual - Page 247
SSL Configuration, SSL Configuration and Ciphersuite menu
View all D-Link DGS-3426 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 247 highlights
xStack DGS-3400 Series Layer 2 Gigabit Ethernet Managed Switch Parameter Description Certificate Type Server IP Certificate File Name Key File Name Select Local to specify certificate type. Enter the IPv4 address of the TFTP server where the certificate files are located. Enter the path and the filename of the certificate file to download. This file must have a .der extension. (Ex. c:/cert.der) Enter the path and the filename of the key file to download. This file must have a .der extension (Ex. c:/pkey.der) Click Apply to implement changes made. SSL Configuration This screen will allow the user to enable SSL on the Switch and implement any one or combination of listed ciphersuites on the Switch. A ciphersuite is a security string that determines the exact cryptographic parameters, specific encryption algorithms and key sizes to be used for an authentication session. The Switch possesses four possible ciphersuites for the SSL function, which are all enabled by default. To utilize a particular ciphersuite, disable the unwanted ciphersuites, leaving the desired one for authentication. When the SSL function has been enabled, the web will become disabled. To manage the Switch through the web based management while utilizing the SSL function, the web browser must support SSL encryption and the header of the URL must begin with https://. (Ex. https://xx.xx.xx.xx) Any other method will result in an error and no access can be authorized for the webbased management. To view the following window, click Security > SSL: Figure 10- 39. SSL Configuration and Ciphersuite menu To set up the SSL function on the Switch, configure the following parameters and click Apply. Parameter Description Configuration SSL Status Use the pull down menu to enable or disable the SSL status on the switch. The default is Disabled. Cache Timeout (6086400) This field will set the time between a new key exchange between a client and a host using the SSL function. A new SSL session is established every time the client and host go through a key exchange. Specifying a longer timeout will allow the SSL session to reuse the master key on future connections with that particular host, therefore speeding up the negotiation process. The default setting is 600 seconds. SSL Ciphersuite RSA with RC4 128 MD5 This ciphersuite combines the RSA key exchange, stream cipher RC4 encryption with 128bit keys and the MD5 Hash Algorithm. Use the pull down menu to enable or disable this ciphersuite. This field is Enabled by default. 233