Fips Compliance; Ssl Configuration Task List; Configuring An Ssl Server Policy - H3C S5830V2 Security Configuration Manual

Hide thumbs Also See for S5830V2:
Table of Contents

Advertisement

Figure 62 SSL protocol stack
The following describes the major functions of SSL protocols:
SSL record protocol—Fragments data received from the upper layer, computes and adds MAC to
the data, and encrypts the data.
SSL handshake protocol—Negotiates the cipher suite used for secure communication (including the
symmetric encryption algorithm, key exchange algorithm, and MAC algorithm), authenticates the
server and client, and securely exchanges the key between the server and client. The client and
server use the SSL handshake protocol to establish a session that comprises a set of parameters,
including the session ID, peer digital certificate, cipher suite, and master secret.
SSL change cipher spec protocol—Notifies the receiving party that the subsequent packets are to be
protected and transmitted based on the newly negotiated cipher suite and key.
SSL alert protocol—Sends alert messages to the receiving party. An alert message contains the alert
severity level and a description.

FIPS compliance

The device supports the FIPS mode that complies with NIST FIPS 140-2 requirements. Support for features,
commands, and parameters might differ in FIPS mode (see

SSL configuration task list

Tasks at a glance

Configuring an SSL server policy

Configuring an SSL client policy
Configuring an SSL server policy
An SSL server policy comprises a set of SSL parameters used by the SSL server. An SSL server policy takes
effect only after it is associated with an application.
NOTE:
SSL versions include SSL 2.0, SSL 3.0, and TLS 1.0 (or SSL 3.1). When the device acts as the SSL server,
it can communicate with clients running SSL 3.0 or TLS 1.0, and can identify the SSL 2.0 Client Hello
message from a client supporting both SSL 2.0 and SSL 3.0/TLS 1.0, and notify the client to use SSL 3.0
or TLS 1.0 for communication.
"Configuring
Remarks
Perform this configuration task on the SSL server.
Perform this configuration task on the SSL client.
198
FIPS") and non-FIPS mode.

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5820v2

Table of Contents