Ciphersuite - HP FlexNetwork 7500 Series Command Reference Manual

Hide thumbs Also See for FlexNetwork 7500 Series:
Table of Contents

Advertisement

SSL commands
The device supports the FIPS mode that complies with NIST FIPS 140-2 requirements. Support for
features, commands, and parameters might differ in FIPS mode and non-FIPS mode. For more
information about FIPS mode, see Security Configuration Guide.

ciphersuite

Use ciphersuite to specify the cipher suites supported by an SSL server policy.
Use undo ciphersuite to restore the default.
Syntax
In non-FIPS mode:
ciphersuite
dhe_rsa_aes_256_cbc_sha
ecdhe_ecdsa_aes_128_cbc_sha256
ecdhe_ecdsa_aes_256_cbc_sha384
ecdhe_rsa_aes_128_cbc_sha256
ecdhe_rsa_aes_256_cbc_sha384 | ecdhe_rsa_aes_256_gcm_sha384 | exp_rsa_des_cbc_sha
| exp_rsa_rc2_md5 | exp_rsa_rc4_md5 | rsa_3des_ede_cbc_sha | rsa_aes_128_cbc_sha |
rsa_aes_128_cbc_sha256
rsa_des_cbc_sha | rsa_rc4_128_md5 | rsa_rc4_128_sha } *
undo ciphersuite
In FIPS mode:
ciphersuite { ecdhe_ecdsa_aes_128_cbc_sha256 | ecdhe_ecdsa_aes_256_cbc_sha384 |
ecdhe_ecdsa_aes_128_gcm_sha256
ecdhe_rsa_aes_128_cbc_sha256
ecdhe_rsa_aes_256_cbc_sha384 | ecdhe_rsa_aes_256_gcm_sha384 | rsa_aes_128_cbc_sha
| rsa_aes_128_cbc_sha256 | rsa_aes_256_cbc_sha | rsa_aes_256_cbc_sha256 } *
undo ciphersuite
Default
An SSL server policy supports all cipher suites.
Views
SSL server policy view
Predefined user roles
network-admin
mdc-admin
Parameters
dhe_rsa_aes_128_cbc_sha: Specifies the cipher suite that uses key exchange algorithm DHE RSA,
data encryption algorithm 128-bit AES_CBC, and MAC algorithm SHA.
dhe_rsa_aes_128_cbc_sha256: Specifies the cipher suite that uses key exchange algorithm DHE
RSA, data encryption algorithm 128-bit AES_CBC, and MAC algorithm SHA256.
dhe_rsa_aes_256_cbc_sha: Specifies the cipher suite that uses key exchange algorithm DHE RSA,
data encryption algorithm 256-bit AES_CBC, and MAC algorithm SHA.
dhe_rsa_aes_256_cbc_sha256: Specifies the cipher suite that uses key exchange algorithm DHE
RSA, data encryption algorithm 256-bit AES_CBC, and MAC algorithm SHA256.
{
dhe_rsa_aes_128_cbc_sha
|
rsa_aes_256_cbc_sha
|
dhe_rsa_aes_128_cbc_sha256
|
dhe_rsa_aes_256_cbc_sha256
|
ecdhe_ecdsa_aes_128_gcm_sha256
|
ecdhe_ecdsa_aes_256_gcm_sha384
|
ecdhe_rsa_aes_128_gcm_sha256
|
ecdhe_ecdsa_aes_256_gcm_sha384
|
ecdhe_rsa_aes_128_gcm_sha256
505
|
rsa_aes_256_cbc_sha256
|
|
|
|
|
|
|
|

Advertisement

Table of Contents
loading

Table of Contents