Specifying Cipher Suites; Figure 4-2 Cipher Suite Algorithms - Cisco 11503 - CSS Content Services Switch Configuration Manual

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Chapter 4
Configuring SSL Termination

Specifying Cipher Suites

Note
OL-5655-01
The SSL protocol supports a variety of different cryptographic algorithms, or
ciphers, for use in operations such as authenticating the server and client to each
other, transmitting certificates, and establishing session keys. Clients and servers
may support different cipher suites, or sets of ciphers, depending on various
factors such as the version of SSL they support, company policies regarding
acceptable encryption strength, and government restrictions on export of
SSL-enabled software. Among its other functions, the SSL handshake protocol
determines how the server and client negotiate which cipher suites they will use
to authenticate each other to transmit certificates and to establish session keys.
Exportable cipher suites are those cipher suites that are considered not to be as
strong as some of the other cipher suites (for example, 3DES or RC4 with 128-bit
encryption) as defined by U.S. export restrictions on software products.
Exportable cipher suites may be exported to most countries from the United
States, and provide the strongest encryption available for exportable products.
Each cipher suite specifies a set of key exchange algorithms.
summarizes the algorithms associated with the rsa-export-with-rc4-40-md5
cipher suite.
Figure 4-2
Cipher Suite Algorithms
Rivest, Shamir and Adelman
(RSA) Key Exchange Algorithm
Use the ssl-server number cipher command to assign a cipher suite for the SSL
proxy list. The cipher suite that you choose must correlate to the certificates and
keys that you have either imported to or generated on the CSS. For example, if
you choose all-cipher-suites, you must have an RSA certificate and key, a DSA
certificate and key, and a Diffie-Hellman parameter file prior to activating the SSL
proxy list.
Configuring Virtual SSL Servers for an SSL Proxy List
rsa-export-with-rc4-40-md5
Indicates the
Data Encryption
cipher suite is
Algorithm
Exportable
Cisco Content Services Switch SSL Configuration Guide
Figure 4-2
Message Authentication
Algorithm
4-11

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents