399
| rsa_aes_256_cbc_sha |
rsa_aes_256_cbc_sha256
}
6. Specify the
SSL protocol
version for the SSL client
policy.
In Release 1111:
• In non-FIPS mode:
version { ssl3.0 | tls1.0 }
• In FIPS mode:
version tls1.0
In Release 1121 and later:
• In non-FIPS mode:
version { ssl3.0 | tls1.0 |
tls1.1 | tls1.2 }
• In FIPS mode:
version { tls1.0 | tls1.1 |
tls1.2 }
By default, an SSL client policy
uses TLS 1.0.
To ensure security, do not
specify SSL 3.0 for an SSL client
policy.
7.
auth
digital certificates.
server-verify enable
authentication is enabled.
Displaying and maintaining SSL
Execute display commands in any view.
Display cryptographic library version information.
(Available in Release 1121 and later.)
display crypto version
Display SSL server policy information.
display ssl server-policy
[ policy-name
]
Display SSL client policy information.
display ssl client-policy
[
policy-name
]