EasyManuals Logo

Cisco 11503 - CSS Content Services Switch Configuration Guide

Cisco 11503 - CSS Content Services Switch
250 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #93 background imageLoading...
Page #93 background image
4-11
Cisco Content Services Switch SSL Configuration Guide
OL-5655-01
Chapter 4 Configuring SSL Termination
Configuring Virtual SSL Servers for an SSL Proxy List
Specifying Cipher Suites
The SSL protocol supports a variety of different cryptographic algorithms, or
ciphers, for use in operations such as authenticating the server and client to each
other, transmitting certificates, and establishing session keys. Clients and servers
may support different cipher suites, or sets of ciphers, depending on various
factors such as the version of SSL they support, company policies regarding
acceptable encryption strength, and government restrictions on export of
SSL-enabled software. Among its other functions, the SSL handshake protocol
determines how the server and client negotiate which cipher suites they will use
to authenticate each other to transmit certificates and to establish session keys.
Note Exportable cipher suites are those cipher suites that are considered not to be as
strong as some of the other cipher suites (for example, 3DES or RC4 with 128-bit
encryption) as defined by U.S. export restrictions on software products.
Exportable cipher suites may be exported to most countries from the United
States, and provide the strongest encryption available for exportable products.
Each cipher suite specifies a set of key exchange algorithms. Figure 4-2
summarizes the algorithms associated with the rsa-export-with-rc4-40-md5
cipher suite.
Figure 4-2 Cipher Suite Algorithms
Use the ssl-server number cipher command to assign a cipher suite for the SSL
proxy list. The cipher suite that you choose must correlate to the certificates and
keys that you have either imported to or generated on the CSS. For example, if
you choose all-cipher-suites, you must have an RSA certificate and key, a DSA
certificate and key, and a Diffie-Hellman parameter file prior to activating the SSL
proxy list.
78265
rsa-export-with-rc4-40-md5
Rivest, Shamir and Adelman
(RSA) Key Exchange Algorithm
Message Authentication
Algorithm
Indicates the
cipher suite is
Exportable
Data Encryption
Algorithm

Table of Contents

Other manuals for Cisco 11503 - CSS Content Services Switch

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 11503 - CSS Content Services Switch and is the answer not in the manual?

Cisco 11503 - CSS Content Services Switch Specifications

General IconGeneral
BrandCisco
Model11503 - CSS Content Services Switch
CategorySwitch
LanguageEnglish

Related product manuals