Configuring An Ssl Client Policy; Configuration Prerequisites; Configuration Procedure; Displaying And Maintaining Ssl - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

Configuring an SSL
Client Policy
Configuration
Prerequisites

Configuration Procedure

Displaying and
Maintaining SSL
To do...
Set the maximum number of
cached sessions and the
caching timeout time
Enable certificate-based SSL
client authentication
n
If you enable client authentication here, you must request a local certificate for the
client.
An SSL client policy is a set of SSL parameters for a client to use when connecting
to the server. An SSL client policy takes effect only after it is associated with an
application layer protocol.
Before configuring an SSL client policy, you must configure a PKI domain first. For
details about PKI domain, refer to
Follow these steps to configure an SSL client policy:
To do...
Enter system view
Create an SSL client policy
and enter its view
Specify a PKI domain used for
the SSL client policy
Specify the preferred cipher
suite for the SSL client policy
Specify the SSL protocol
version for the SSL client
policy
n
If you enable client authentication on the server, you must request a local
certificate for the client.
To do...
Display SSL server policy
information
Display SSL client policy
information

Configuring an SSL Client Policy

Use the command...
session { cachesize size |
timeout time } *
client-verify enable
"Configuring a PKI Domain" on page
Use the command...
system-view
ssl client-policy policy-name Required
pki-domain domain-name
prefer-cipher
{ rsa_3des_ede_cbc_sha |
rsa_aes_128_cbc_sha |
rsa_aes_256_cbc_sha |
rsa_des_cbc_sha |
rsa_rc4_128_md5 |
rsa_rc4_128_sha }
version { ssl3.0 | tls1.0 }
Use the command...
display ssl server-policy
{ policy-name | all }
display ssl client-policy
{ policy-name | all }
1955
Remarks
Optional
The defaults are as follows:
500 for the maximum number
of cached sessions,
3600 seconds for the caching
timeout time.
Optional
Not enabled by default
1833.
Remarks
-
Required
No PKI domain is configured
by default.
Optional
rsa_rc4_128_md5 by default
Optional
TLS1.0 by default
Remarks
Available in any view

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents