Setting Stronger Ciphers
Setting Stronger Ciphers
The Stronger Ciphers option presents a choice of 168, 128, or 56-bit secret key size
for access, or no restriction. You can specify a file to be served when the restriction
is not met. If no file is specified, Enterprise Server returns a "Forbidden" status.
If you select a key size for access that is not consistent with the current cipher
settings under Security Preferences, Enterprise Server displays a popup dialog
warning that you need to enable ciphers with larger secret key sizes.
The implementation of the key size restriction is now based on an NSAPI
PathCheck
directive is:
PathCheck fn="ssl-check" [secret-keysize=<nbits>]
[bong-file=<filename>]
where
<filename>
met.
PathCheck
parameter is not specified. If the secret key size for the current session is less than
the specified
PROTOCOL_FORBIDDEN
"path" variable is set to the
restriction is not met, the SSL session cache entry for the current session is
invalidated, so that a full SSL handshake will occur the next time the same client
connects to the server.
NOTE
To Set Stronger Ciphers, perform the following steps:
Access the Server Manager and select the server instance from the drop-down
1.
list.
Click the Virtual Server Class tab.
2.
Select a class from the drop-down list and click Manage.
3.
The Class Manger page appears.
Choose the Content Mgmt tab.
4.
130
Netscape Enterprise Server Administrator's Guide • April 2002 (Draft)
directive in
obj.conf
is the minimum number of bits required in the secret key, and
<nbits>
is the name of a file (not a URI) to be served if the restriction is not
returns
REQ_NOACTION
secret-keysize
if
bong-file
The Stronger Ciphers form removes any Service
directives that it finds in an object when it adds a
fn=ssl-check
, rather than Service
if SSL is not enabled, or if the
, the function returns
is not specified, or else
bong-file <filename>
.
. This
fn=key-toosmall
secret-keysize
with a status of
REQ_ABORTED
REQ_PROCEED
. Also, when a key size
fn=key-toosmall
PathCheck
, and the
Need help?
Do you have a question about the NETSCAPE ENTREPRISE SERVER 6.1 - 04-2002 ADMINISTRATOR and is the answer not in the manual?
Questions and answers