396
dhe_rsa_aes_128_cbc_sha
256 |
dhe_rsa_aes_256_cbc_sha
|
dhe_rsa_aes_256_cbc_sha
256 |
ecdhe_ecdsa_aes_128_cbc
_sha256 |
ecdhe_ecdsa_aes_128_gc
m_sha
ecdhe_ecdsa_aes_256_cbc
_sha384 |
ecdhe_ecdsa_aes_256_gc
m_sha384 |
ecdhe_rsa_aes_128_cbc_s
ha256 |
ecdhe_rsa_aes_128_gcm_s
ha256 |
ecdhe_rsa_aes_256_cbc_s
ha384 |
ecdhe_rsa_aes_256_gcm_s
ha384 |
exp_rsa_des_cbc_sha |
exp_rsa_rc2_md5 |
exp_rsa_rc4_md5 |
rsa_3des_ede_cbc_sha |
rsa_aes_128_cbc_sha |
rsa_aes_128_cbc_sha256 |
rsa_aes_256_cbc_sha |
rsa_aes_256_cbc_sha256 |
rsa_des_cbc_sha |
rsa_rc4_128_md5 |
rsa_rc4_128_sha } *
• In FIPS mode:
ciphersuite
{ ecdhe_ecdsa_aes_128_cb
c_sha256 |
ecdhe_ecdsa_aes_128_gc
m_sha
ecdhe_ecdsa_aes_256_cbc
_sha384 |
ecdhe_ecdsa_aes_256_gc
m_sha384 |
ecdhe_rsa_aes_128_cbc_s
ha256 |
ecdhe_rsa_aes_128_gcm_s
ha256 |
ecdhe_rsa_aes_256_cbc_s
ha384 |
ecdhe_rsa_aes_256_gcm_s
ha384 |
rsa_aes_128_cbc_sha |
rsa_aes_128_cbc_sha256 |
rsa_aes_256_cbc_sha |
rsa_aes_256_cbc_sha256} *
7.
Set the maximum number of
sessions that the SSL server
can cache.
session
cachesize
size
By default, an SSL server can
sessions.
8. Enable the SSL server to
authenticate SSL clients
through digital certificates.
client-verify enable
authentication is disabled.