Displaying And Maintaining Ssl - HP FlexFabric 5930 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 5930 Series:
Table of Contents

Advertisement

Step
3.
(Optional.) Specify a PKI
domain for the SSL client policy.
4.
Specify the preferred cipher
suite for the SSL client policy.
5.
Specify the SSL version for the
SSL client policy.
6.
Enable the SSL client to
authenticate servers through
digital certificates.

Displaying and maintaining SSL

Execute display commands in any view.
Task
Display SSL server policy information.
Display SSL client policy information.
Command
pki-domain domain-name
prefer-cipher
{ dhe_rsa_aes_128_cbc_sha |
dhe_rsa_aes_256_cbc_sha |
exp_rsa_des_cbc_sha |
exp_rsa_rc2_md5 |
exp_rsa_rc4_md5 |
rsa_3des_ede_cbc_sha |
rsa_aes_128_cbc_sha |
rsa_aes_256_cbc_sha |
rsa_des_cbc_sha |
rsa_rc4_128_md5 |
rsa_rc4_128_sha }
version { ssl3.0 | tls1.0 }
server-verify enable
Command
display ssl server-policy [ policy-name ]
display ssl client-policy [ policy-name ]
141
Remarks
By default, no PKI domain is
specified for an SSL client policy.
If the SSL server authenticates the
SSL client through a digital
certificate, you must use this
command to specify a PKI
domain and request a local
certificate for the SSL client
through the PKI domain.
For information about how to
create and configure a PKI
domain, see
"Configuring
The default preferred cipher suite
is rsa_rc4_128_md5.
By default, an SSL client policy
uses TLS 1.0.
The default setting is enabled.
PKI."

Advertisement

Table of Contents
loading

Table of Contents