HP FlexNetwork 10500 Series Security Configuration Manual page 249

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
2.
(Optional.) Disable specific
SSL protocol versions on the
device.
3.
(Optional.) Disable SSL
session renegotiation.
4.
Create an SSL server policy
and enter its view.
5.
(Optional.) Specify a PKI
domain for the SSL server
policy.
Command
In non-FIPS mode:
ssl version { ssl3.0 | tls1.0 |
tls1.1 } * disable
In FIPS mode:
ssl version { tls1.0 | tls1.1 } *
disable
ssl renegotiation disable
ssl server-policy policy-name
pki-domain domain-name
235
Remarks
By default:
In non-FIPS mode, the
device supports SSL 3.0,
TLS 1.0, TLS 1.1, and
TLS 1.2.
In FIPS mode, the device
supports TLS 1.0, TLS
1.1, and TLS 1.2.
By default, SSL session
renegotiation is enabled.
By default, no SSL server
policies exist on the device.
By default, no PKI domain is
specified for an SSL server
policy.
If SSL server authentication is
required, you must specify a
PKI domain and request a
local certificate for the SSL
server in the domain.
For information about how to
create and configure a PKI
domain, see
"Configuring
PKI."

Advertisement

Table of Contents
loading

Table of Contents