EasyManuals Logo

Cisco 11503 - CSS Content Services Switch Configuration Guide

Cisco 11503 - CSS Content Services Switch
250 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #179 background imageLoading...
Page #179 background image
6-21
Cisco Content Services Switch SSL Configuration Guide
OL-5655-01
Chapter 6 Configuring SSL Initiation
Configuring Back-End SSL Servers in an SSL Initiation Proxy List
Configuring the DSA Certificate Name
To configure the back-end server DSA certificate, use the backend-server
number dsacert name command. The certificate must already be loaded on the
SCM. If the certificate name does not exist, the CSS logs an error message. Enter
a name for the DSA certificate as an unquoted text string from 1 to 31 characters.
For example, to configure a DSA certificate named mydsacert, enter:
(config-ssl-proxy-list[ssl_list1])# backend-server 1 dsacert mydsacert
To remove a DSA cert from the SSL proxy list, enter:
(config-ssl-proxy-list[ssl_list1])# no backend-server 1 dsacert
Configuring the DSA Key Filename
To configure the back-end server DSA key name, use the backend-server number
dsakey name command. The key pair must already be loaded on the SCM. If the
key pair name does not exist, the CSS logs an error message. Enter a name for the
DSA key pair as an unquoted text string from 1 to 31 characters.
For example, to configure a DSA key pair named mydsakey, enter:
(config-ssl-proxy-list[ssl_list1])# backend-server 1 dsakey mydsakey
To remove an DSA key pair from the SSL proxy list, enter:
(config-ssl-proxy-list[ssl_list1])# no backend-server 1 dsakey
Configuring CA Certificates for Server Authentication
If the it has the public key of a particular certificate authority (CA), the CSS can
verify that the server certificate was signed by that CA. The CSS obtains the
public key of the CA from the CA certificate. If you configure a CA certificate
name in an SSL initiation proxy list, the CSS can use the public key in the
certificate to verify the digital signature of the CA in the server certificate.
Defining a CA certificate in the SSL initiation proxy list indicates to the CSS that
you want to verify the server certificate.
Note By default, SSL servers are not authenticated.

Table of Contents

Other manuals for Cisco 11503 - CSS Content Services Switch

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 11503 - CSS Content Services Switch and is the answer not in the manual?

Cisco 11503 - CSS Content Services Switch Specifications

General IconGeneral
BrandCisco
Model11503 - CSS Content Services Switch
CategorySwitch
LanguageEnglish

Related product manuals