Cisco Explorer 4700 Installationsanleitung Seite 356

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 648
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 355
9-30
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 9 Configuring SSL
Configuring SSL OCSP Service
Step 11 In the Parameter Maps field, select the SSL parameter map to associate with this SSL proxy server
service.
Step 12 For the Revcheck priority order, select one of the following to set the priority for the revocation check:
N/A—Indicates that this field is not applicable.
CRL-OCSP—The ACE uses the CRLs first to determine the revocation status, and then the OCSP
servers.
OCSP-CRL—The ACE uses the OCSP servers first to determine the revocation status, and then the
CRLs.
Step 13 Do the following:
Click Deploy Now to deploy this configuration on the ACE appliance.
Click Cancel to exit this procedure without saving your entries and to return to the Proxy Service
table.
Click Next to save your entries and to add another proxy service.
Related Topics
Configuring SSL, page 9-1
Importing SSL Certificates, page 9-8
Importing SSL Key Pairs, page 9-12
Configuring SSL Parameter Maps, page 9-19
Configuring SSL Chain Group Parameters, page 9-25
Configuring SSL CSR Parameters, page 9-26
Configuring SSL OCSP Service, page 9-30
Configuring SSL OCSP Service
SSL Online Certificate Status Protocol (OCSP) service defines the host server for certificate revocation
checks using OCSP. The OCSP server, also known as the OCSP responder, maintains or obtains the
information about the certificates issued by different CAs that are revoked and possibly non-revoked,
and provides this information when requested by OCSP clients. OCSP can provide latest information
about the revocation status of the certificate. Use of OCSP removes the need to download and cache the
CRLs which could be very large in sizes and impose large memory requirements on systems.
You can configure a maximum of 64 OCSP server configurations system-wide on the ACE. You can
configure all of these servers in a single or multiple contexts.
Use this procedure to define the attributes that the ACE appliance is to use during SSL handshakes so
that it can act as an SSL server.
Assumption
Configure OCSP on an associated proxy service.
You can configure both OCSP and CRLs for authentication.
Seitenansicht 355
1 2 ... 351 352 353 354 355 356 357 358 359 360 361 ... 647 648

Kommentare zu diesen Handbüchern

Keine Kommentare