beautypg.com

H3C Technologies H3C SecBlade LB Cards User Manual

Page 162

background image

151

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Create an SSL server policy
and enter its view.

ssl server-policy policy-name N/A

3.

Specify a PKI domain for the
SSL server policy.

pki-domain domain-name

Optional.
By default, no PKI domain is
specified for an SSL server policy,

and the SSL server generates and

signs a certificate for itself and
does not obtain a certificate from a

CA server.
If SSL clients authenticate the server
through a digital certificate, you

must use this command to specify a
PKI domain and request a local

certificate for the SSL server in the

PKI domain.
For information about how to
configure a PKI domain, see

"Configuring PKI."

4.

Specify the cipher suite(s) for
the SSL server policy to

support.

ciphersuite [rsa_aes_128_cbc_sha
| rsa_des_cbc_sha |

rsa_rc4_128_md5 |
rsa_rc4_128_sha ] *

Optional.
By default, an SSL server policy

supports all cipher suites.

5.

Set the handshake timeout

time for the SSL server.

handshake timeout time

Optional.
3600 seconds by default.

6.

Set the SSL connection close
mode.

close-mode wait

Optional.
Not wait by default.

7.

Set the maximum number of
cached sessions and the

caching timeout time.

session { cachesize size | timeout
time } *

Optional.
The defaults are as follows:

500 for the maximum number

of cached sessions,.

3600 seconds for the caching

timeout time.

8.

Configure the server to require

certificate-based SSL client

authentication.

client-verify enable

Optional.
By default, the SSL server does not
require the client to be

authenticated.

9.

Enable SSL client weak
authentication.

client-verify weaken

Optional.
Disabled by default.
This command takes effect only
when the client-verify enable

command is configured.

This manual is related to the following products: