Specifying The Rsa Key Pair Name; Specifying The Dsa Certificate Name - Cisco 11503 - CSS Content Services Switch Configuration Manual

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Chapter 4
Configuring SSL Termination

Specifying the RSA Key Pair Name

Specifying the DSA Certificate Name

OL-5655-01
To remove an RSA certificate association from a specific virtual SSL server,
enter:
(config-ssl-proxy-list[ssl_list1])# no ssl-server 20 rsacert
To identify the name of an RSA key pair association. RSA key pairs are required
before another device (client or server) can exchange an SSL certificate with the
CSS, use the ssl-server number rsakey name command. To see a list of existing
RSA key pair associations, use the ssl-server number rsakey ? command.
The RSA key pair must already be loaded on the CSS and an association made
(see
Chapter 3, Configuring SSL Certificates and
RSA key pair association, when you activate the SSL proxy list, the CSS logs an
error message and does not activate the list.
For example, to specify a previously defined RSA key pair association named
rsakey, enter:
(config-ssl-proxy-list[ssl_list1])# ssl-server 20 rsakey myrsakey1
To remove an RSA key pair association from a specific virtual SSL server, enter:
(config-ssl-proxy-list[ssl_list1])# no ssl-server 20 rsakey
To identify the name of a DSA certificate association that is to be used in the
exchange of digital signatures, use the ssl-server number dsacert name
command. To see a list of existing DSA certificate associations, use the ssl-server
number dsacert ? command.
The specified DSA certificate must already be loaded on the CSS and an
association made (see
is not a proper RSA certificate association, when you activate the SSL proxy list,
the CSS logs an error message and does not activate the list.
For example, to specify a previously defined DSA certificate association named
dsacert, enter:
(config-ssl-proxy-list[ssl_list1])# ssl-server 20 dsacert mydsacert1
To remove a DSA certificate association from a specific virtual SSL server, enter:
(config-ssl-proxy-list[ssl_list1])# no ssl-server 20 dsacert
Configuring Virtual SSL Servers for an SSL Proxy List
Chapter 3, Configuring SSL Certificates and
Cisco Content Services Switch SSL Configuration Guide
Keys). If there is not a proper
Keys). If there
4-9

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents