6-5
Cisco Content Services Switch SSL Configuration Guide
OL-5655-01
Chapter 6 Configuring SSL Initiation
Configuring Back-End SSL Servers in an SSL Initiation Proxy List
Once you create a back-end server in an SSL proxy list, configure a IP address
that corresponds to the address of the service and a server IP address that
corresponds to the IP address of the SSL initiation server. Configure the other
optional proxy-list parameters if desired, and then activate the SSL proxy list. To
make the back-end server work for SSL initiation, you must configure the
back-end server type as initiation.
After you configure and activate the SSL proxy list, add the list to an SSL
initiation service. When you activate the service, the CSS sends the configuration
data to the SSL module.
The following sections describe:
• Creating a Back-End Server in an SSL Initiation Proxy List
• Configuring the Back-End Server as an SSL Initiation Server
• Configuring an IP Address for the SSL Initiation Server
• Configuring a Port for the SSL Initiation Server
• Configuring the SSL Server IP Address
• Configuring the SSL Server Port
• Configuring SSL Version
• Configuring the Available Cipher Suites
• Configuring SSL Session Cache Timeout
• Configuring SSL Session Handshake Renegotiation
• Configuring TCP Virtual Client Connections Timeout Values
• Configuring TCP Server-Side Connection Timeout Values on the SSL
Module
• Specifying the Nagle Algorithm for Client-Side Connections
• Specifying the TCP Buffering for SSL TCP Connections
• Configuring Client Certificates and Keys
• Configuring CA Certificates for Server Authentication