Configuring Secure Http Servers And Clients; Default Ssl Configuration; Ssl Configuration Guidelines; Configuring A Ca Trustpoint - Cisco Catalyst 2360 Software Configuration Manual

Ios 12.2(53)ey
Hide thumbs Also See for Catalyst 2360:
Table of Contents

Advertisement

Chapter 7
Configuring Switch-Based Authentication
4.
RSA (in conjunction with the specified encryption and digest algorithm combinations) is used for both
key generation and authentication on SSL connections. This usage is independent of whether or not a
CA trustpoint is configured.

Configuring Secure HTTP Servers and Clients

These sections contain this configuration information:

Default SSL Configuration

The standard HTTP server is enabled.
SSL is enabled.
No CA trustpoints are configured.
No self-signed certificates are generated.

SSL Configuration Guidelines

When SSL is used in a switch cluster, the SSL session terminates at the cluster commander. Cluster
member switches must run standard HTTP.
Before you configure a CA trustpoint, you should ensure that the system clock is set. If the clock is not
set, the certificate is rejected due to an incorrect date.

Configuring a CA Trustpoint

For secure HTTP connections, we recommend that you configure an official CA trustpoint.
A CA trustpoint is more secure than a self-signed certificate.
Beginning in privileged EXEC mode, follow these steps to configure a CA trustpoint:
Command
Step 1
configure terminal
Step 2
hostname hostname
Step 3
ip domain-name domain-name
OL-19808-01
SSL_RSA_WITH_3DES_EDE_CBC_SHA—RSA key exchange with 3DES and DES-EDE3-CBC
for message encryption and SHA for message digest
Default SSL Configuration, page 7-39
SSL Configuration Guidelines, page 7-39
Configuring a CA Trustpoint, page 7-39
Configuring the Secure HTTP Server, page 7-40
Configuring the Secure HTTP Client, page 7-42
Purpose
Enter global configuration mode.
Specify the hostname of the switch (required only if you have not
previously configured a hostname). The hostname is required for security
keys and certificates.
Specify the IP domain name of the switch (required only if you have not
previously configured an IP domain name). The domain name is required
for security keys and certificates.
Configuring the Switch for Secure Socket Layer HTTP
Catalyst 2360 Switch Software Configuration Guide
7-39

Advertisement

Table of Contents
loading

Table of Contents