Cisco 11503 - CSS Content Services Switch Configuration Manual page 62

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Overview of SSL Certificates and Keys
The CSS require certificates and keys for:
Before configuring SSL termination, client authentication, or SSL initiation, you
must load a digital certificate on the CSS disk (flash disk or hard disk). For SSL
termination or SSL initiation, you must also load a public/private key pair on the
CSS. The CSS stores digital certificates and key pairs in encrypted files in a
secure area on the CSS.
For server and client certificates, you can use files received from a CA, import the
certificate and keys from an existing secure server, or generate your own
certificate and keys on the CSS. The CSS supports the generation of certificates
and keys directly within the CSS for purposes of testing. Your requirement to use
generated certificates and keys instead of certificates and keys from a trusted
authority depends on your environment. For example, the use of the CSS and SSL
for a company's internal website may not require the use of certificates from a
trusted CA. A certificate and key pair generated within the CSS may be sufficient
to satisfy the intranet SSL requirement.
After you import certificates or key pairs on the CSS, you must associate them to
filenames. You will use these filenames when you configure SSL termination,
client authentication, or SSL initiation.
When importing or exporting certificates and keys with the CSS, ensure that the
Caution
CSS is not configured to perform a network boot from a network-mounted file
system on a remote system (operating the CSS in a diskless environment). The
network-mounted method of CSS booting is not supported with SSL termination;
the certificates and keys must be local to the CSS and SSL module.
To implement good security policies when importing or generating SSL
Note
certificates and key pairs, administrators should understand the user modes of the
CSS and have strong password policies to protect those user modes. For more
information, refer to the Cisco Content Services Switch Command Reference,
Chapter 2, CLI Commands, the "(config) username-technician" section.
Cisco Content Services Switch SSL Configuration Guide
3-2
SSL termination - You must obtain a server certificate and key.
SSL initiation - You must obtain a client certificate and key.
Client authentication - You must obtain a trusted CA certificate from the CA
to verify that the client certificate and certificate revocation list (CRL) were
issued by the CA.
Chapter 3
Configuring SSL Certificates and Keys
OL-5655-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents