Enabling Client Authentication; Specifying Ca Certificates For Client Certificate Verification - Cisco 11503 - CSS Content Services Switch Configuration Manual

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Configuring Virtual SSL Servers for an SSL Proxy List

Enabling Client Authentication

Specifying CA Certificates for Client Certificate Verification

Note
Cisco Content Services Switch SSL Configuration Guide
4-16
By default, client authentication is disabled on the CSS. The authentication
option of the ssl-server command allows you to enable or disable client
authentication. For example, to enable client authentication, enter:
(config-ssl-proxy-list[ssl_list1])# ssl-server 20 authentication
enable
To reset the default setting of disabling client authentication, enter:
(config-ssl-proxy-list[ssl_list1])# no ssl-server 20 authentication
You can also reset the default setting of disabling client authentication by using
the disable option. For example, enter:
(config-ssl-proxy-list[ssl_list1])# ssl-server 20 authentication
disable
After you enable client authentication on the CSS, you must specify a CA
certificate that the CSS uses to verify client certificates.
CA certificates contain the public key of the CA. If a server has the CA public key,
it can verify that a client certificate was signed by the CA. If you assign a CA
certificate to a virtual SSL server, the CSS uses the key in the certificate to verify
the digital signature in the client certificate.
You must configure a CA certificate before you activate the SSL proxy list.
Before you configure the certificate on a virtual SSL server, you must import a
CA certificate on the CSS and then associate it with a filename. For information
on importing a CA certificate, see the
Private Keys"
section in
information on associating a certificate with a filename, see the
Certificate with a File"
You must configure at least one certificate; however, you can configure a
maximum of four certificates. If you try to configure more than four certificates,
the CSS displays an error message.
"Importing or Exporting Certificates and
Chapter 3, Configuring SSL Certificates and
also in
Chapter 3, Configuring SSL Certificates and
Chapter 4
Configuring SSL Termination
"Associating a
Keys. For
Keys.
OL-5655-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents