Chapter 7 Displaying SSL Configuration Information and Statistics
Showing SSL Module Statistics
7-22
Cisco Content Services Switch SSL Configuration Guide
OL-5655-01
Rehandshake TimerAlloc
failed
Number of times the SSL module was unable to
allocate the Rehandshake Timer.
Successful client
authentications
Number of times that the CSS successfully
authenticated a client certificate.
Client authentication
failures
Number of times that the CSS could not authenticate
a client certificate.
Unknown issuer
certificates
Number of times that the CSS could not identify the
issuer of a client certificate.
Signature unable to
decrypt
Number of times that the CSS could not decrypt the
signature on a client certificate.
Invalid issuer keys Number of times that the CSS identified an invalid
key of a client certificate.
Not yet valid certificate Number of times that the CSS received a certificate
that had not been validated by a CA at that time.
Expired certificates Number of times that the CSS received a certificate
with an expired time stamp.
Revoked certificate Number of times that the CSS received a client
certificate revoked by the issuer.
CRLs not obtained from
host
A timeout occurred when the CSS tried to obtain a
CRL from a host.
CRLs obtained but failed
to load
The CSS successfully obtained the CRL but the CRL
failed to load.
CRLs with invalid
signatures
Number of times that the CSS could not validate the
signer of the CRL with the signer certificate on the
CSS.
CRL out of memory error Number of times that the SSL module was out of
memory and could not store the CRL. When a CRL
cannot be stored in memory, all incoming client
authentications will fail.
Session Cache Statistics
Handshakes Accepted
from Client
Number of handshakes that the SSL module
accepted from clients.
Table 7-11 Field Descriptions for the show ssl statistics Command (continued)
Field Description