HP 5500 HI Series Configuration Manual page 357

Security
Hide thumbs Also See for 5500 HI Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Create an SSL server policy
and enter its view.
3.
Specify a PKI domain for the
SSL server policy.
4.
Specify the cipher suites for
the SSL server policy to
support.
5.
Set the handshake timeout
time for the SSL server.
6.
Set the SSL connection close
mode.
7.
Set the maximum number of
cached sessions and the
caching timeout time.
Command
system-view
ssl server-policy policy-name
pki-domain domain-name
In non-FIPS mode:
ciphersuite
[ rsa_3des_ede_cbc_sha |
rsa_aes_128_cbc_sha |
rsa_aes_256_cbc_sha |
rsa_des_cbc_sha |
rsa_rc4_128_md5 |
rsa_rc4_128_sha ] *
In FIPS mode:
ciphersuite
[ dhe_rsa_aes_128_cbc_sha |
dhe_rsa_aes_256_cbc_sha |
rsa_aes_128_cbc_sha |
rsa_aes_256_cbc_sha ] *
handshake timeout time
close-mode wait
session { cachesize size | timeout
time } *
344
Remarks
N/A
N/A
Optional.
By default, no PKI domain is
specified for an SSL server policy.
The SSL server generates a
certificate itself instead of
requesting one from the CA.
After you specify a PKI domain, the
SSL server requests a certificate
through the PKI domain.
If the client requires
certificate-based authentication for
the SSL server, you must use this
command to specify a PKI domain.
For more information about PKI
domain configuration, see
"Configuring
PKI."
Optional.
By default, an SSL server policy
supports all cipher suites.
Optional.
3600 seconds by default.
Optional.
By default, an SSL server sends a
close-notify alert message to the
client and closes the connection
without waiting for the close-notify
alert message from the client.
Optional.
The defaults are as follows:
500 for the maximum number
of cached sessions.
3600 seconds for the caching
timeout time.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents