3Com Switch 4800G 24-Port Configuration Manual page 1209

Switch 4800g family 24-port, pwr 24-port, 48-port, pwr 48-port, 24-port sfp
Hide thumbs Also See for Switch 4800G 24-Port:
Table of Contents

Advertisement

n
SSL Server Policy
Configuration Example
c
To do...
Set the maximum number
of cached sessions and the
caching timeout time
Enable certificate-based
SSL client authentication
If you enable client authentication here, you must request a local certificate for the
client.
Network requirements
A switch works as the HTTPS server.
A host works as the client and accesses the HTTPS server through HTTP secured
with SSL.
A certificate authentication (CA) issues a certificate to the switch.
CAUTION: In this instance, Windows Server works as the CA and the Simple
Certificate Enrollment Protocol (SCEP) plug-in is installed on the CA.
Network diagram
Figure 358 Network diagram for SSL server policy configuration
Switch
Vlan-int2
10.1.1.1/24
10 .1.1.2/24
Host
Configuration procedure
1 Request a certificate for the switch
# Create a PKI entity named en and configure it.
<Sysname> system-view
[Sysname] pki entity en
[Sysname-pki-entity-en] common-name http-server1
[Sysname-pki-entity-en] fqdn ssl.security.com
[Sysname-pki-entity-en] quit
# Create a PKI domain and configure it.
[Sysname] pki domain 1
[Sysname-pki-domain-1] ca identifier ca1
[Sysname-pki-domain-1] certificate request url http://10.1.2.2/certsrv/mscep/mscep.dll
Use the command...
session { cachesize size |
timeout time } *
client-verify enable
Vlan- int3
10.1.2.1 /24
10.1.2.2/24
CA
Configuring an SSL Server Policy
Remarks
Optional
The defaults are as follows:
500 for the maximum number of
cached sessions,
3600 seconds for the caching
timeout time.
Optional
Not enabled by default
1209

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents