Back-End Ssl - Cisco 11503 - CSS Content Services Switch Configuration Manual

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Chapter 1
Overview of CSS SSL
Overview of the SSL Module Functions in the CSS
An X.509 certificate includes a signature that is generated by signing a message
digest of the entire certificate object using the private key of the CA. A CA
certificate contains the CA public key that verifies the digital signature of the
client certificate. If the server has a CA certificate and thus the public key of the
CA, it can verify that the client certificate was signed by the CA. The CSS allows
you to configure up to four CA certificates per virtual SSL server.
When a CA revokes a client certificate, the CA adds the certificate to a published
list called the Certificate Revocation List (CRL). The CA publicizes this list and
updates it periodically. Clients and servers can access this list through HTTP to
validate a certificate. The CSS allows you to configure a CRL record that defines
how and when to retrieve a CRL onto the CSS. After the CSS retrieves the CRL,
the virtual SSL server can use the downloaded CRL to check the validity of all
client certificates.
For information on configuring client authentication on a CSS virtual SSL server,
including enabling client authentication, verifying CA certificate authenticity,
configuring a CRL record, and assigning it to a virtual SSL server, see
Chapter 4,
Configuring SSL
Termination.

Back-End SSL

A back-end SSL server entry in an SSL proxy list defines the flow from the SSL
module to the back-end SSL server. After receiving encrypted data from a client,
the SSL module, acting as a virtual client by preserving the originating client's IP
address, encrypts the clear text data used for load balancing the flow and initiates
the SSL connection to the back-end server.
On the outbound flow from the CSS, the SSL module responds in the reverse
direction and sends the encrypted data from the server back to the client. For more
information about back-end SSL in the CSS, see
Chapter 5, Configuring
Back-End
SSL.
Cisco Content Services Switch SSL Configuration Guide
1-11
OL-5655-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents