Configuring The Dsa Certificate Name; Configuring The Dsa Key Filename; Configuring Ca Certificates For Server Authentication - Cisco 11503 - CSS Content Services Switch Configuration Manual

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Chapter 6
Configuring SSL Initiation

Configuring the DSA Certificate Name

Configuring the DSA Key Filename

Configuring CA Certificates for Server Authentication

Note
OL-5655-01
To configure the back-end server DSA certificate, use the backend-server
number dsacert name command. The certificate must already be loaded on the
SCM. If the certificate name does not exist, the CSS logs an error message. Enter
a name for the DSA certificate as an unquoted text string from 1 to 31 characters.
For example, to configure a DSA certificate named mydsacert, enter:
(config-ssl-proxy-list[ssl_list1])# backend-server 1 dsacert mydsacert
To remove a DSA cert from the SSL proxy list, enter:
(config-ssl-proxy-list[ssl_list1])# no backend-server 1 dsacert
To configure the back-end server DSA key name, use the backend-server number
dsakey name command. The key pair must already be loaded on the SCM. If the
key pair name does not exist, the CSS logs an error message. Enter a name for the
DSA key pair as an unquoted text string from 1 to 31 characters.
For example, to configure a DSA key pair named mydsakey, enter:
(config-ssl-proxy-list[ssl_list1])# backend-server 1 dsakey mydsakey
To remove an DSA key pair from the SSL proxy list, enter:
(config-ssl-proxy-list[ssl_list1])# no backend-server 1 dsakey
If the it has the public key of a particular certificate authority (CA), the CSS can
verify that the server certificate was signed by that CA. The CSS obtains the
public key of the CA from the CA certificate. If you configure a CA certificate
name in an SSL initiation proxy list, the CSS can use the public key in the
certificate to verify the digital signature of the CA in the server certificate.
Defining a CA certificate in the SSL initiation proxy list indicates to the CSS that
you want to verify the server certificate.
By default, SSL servers are not authenticated.
Configuring Back-End SSL Servers in an SSL Initiation Proxy List
Cisco Content Services Switch SSL Configuration Guide
6-21

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents