Ssl Configuration - Zte ZXR10 2900E series Configuration Manual

Easy-maintenance secure switch
Hide thumbs Also See for ZXR10 2900E series:
Table of Contents

Advertisement

5.47 SSL Configuration

SSL Overview
The
SSL
and transport layer in the network model. Through the data encryption, identification
authentication, and message integrity validation mechanisms, SSL ensures security for
connections established based on reliable application layer protocols (for example, TCP).
The SSL functional module enables the ZXR10 2900E to operate as an SSL server and
complete interaction with a client. The interaction procedure includes SSL handshaking,
and packet monitoring, receiving, parsing and sending. The SSL handshaking procedure
includes negotiating an encryption algorithm, verifying the local certificate on the server,
exchanging keys, and verifying a MAC address. The encryption algorithm, local certificate
on the server, keys, and MAC address are used for data encryption and decryption,
identification authentication, and message integrity validation in a subsequent session.
Encryption certificate management is the prerequisite for SSL handshaking. Certificate
management includes key generation management, local certificate generation on the
server, and root certificate generation on the client.
Users can access the ZXR10 2900E by using browsers and HTTPS to perform Web-based
configuration and management.
Configuring SSL
The SSL configuration includes the following commands:
Command
zte(cfg)#
zte(cfg)#
etwork mask>}
show ssl (all configuration modes)
SSL Configuration Instance
l
Configuration Description
See
Figure
to 192.168.100.110/24. The IP address of the PC is set to 192.168.100.109/24. The
switch operates as the SSL server, and the browser on the PC operates as the SSL
client.
SJ-20130731155059-002|2013-11-27 (R1.0)
protocol is an intermediate protocol. It is located between the application layer
set ssl {enable | disable}
create ca {<A.B.C.D/M>|<A.B.C.D><n
5-62, a layer-3 port is configured on the switch, and the IP address is set
Chapter 5 Service Configuration
Function
Enables or disables the SSL function.
Manages the encryption certificate, and creates
an RSA key, a local certificate on the server and
a root certificate on the client.
Displays the SSL configuration and state.
5-167
ZTE Proprietary and Confidential

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents