Setting Stronger Ciphers - Netscape ENTREPRISE SERVER 6.0 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

If one or more matching entries are found, the server proceeds to verify the entries.
If no matching entries are found, the server will use
search for matching entries. In this example, the server would search for
Whitman
NOTE

Setting Stronger Ciphers

The Stronger Ciphers option presents a choice of 168, 128, or 56-bit secret key size
for
access,
is not met. If no file is specified, Enterprise Server returns a "Forbidden" status.
If you select a key size for access that is not consistent with the current cipher
settings under Security Preferences, Enterprise Server displays a popup dialog
warning that you need to enable ciphers with larger secret key sizes.
The implementation of the key size restriction is now based on an NSAPI
PathCheck
directive is:
PathCheck fn="ssl-check" [secret-keysize=<nbits>]
[bong-file=<filename>]
where
<filename>
met.
PathCheck
parameter is not specified. If the secret key size for the current session is less than
the specified
PROTOCOL_FORBIDDEN
"path" variable is set to the
restriction is not met, the SSL session cache entry for the current session is
invalidated, so that a full SSL handshake will occur the next time the same client
connects to the server.
NOTE
in all entries under
This example assumes the LDAP directory contains entries with the
attribute
certSubjectDN
or no restriction. You can specify a file to be served when the restriction
directive in
obj.conf
is the minimum number of bits required in the secret key, and
<nbits>
is the name of a file (not a URI) to be served if the restriction is not
returns
REQ_NOACTION
secret-keysize
if
bong-file
The Stronger Ciphers form removes any Service
directives that it finds in an object when it adds a
fn=ssl-check
o=Example Corporation, c=US
.
, rather than Service
if SSL is not enabled, or if the
, the function returns
is not specified, or else
bong-file <filename>
.
Chapter 5
Setting Stronger Ciphers
and
DNComps
FilterComps
uid=Walt
.
. This
fn=key-toosmall
secret-keysize
with a status of
REQ_ABORTED
REQ_PROCEED
. Also, when a key size
fn=key-toosmall
PathCheck
Securing Your Enterprise Server
to
, and the
127

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netscape management system 6.0

Table of Contents