Chapter 4
Configuring SSL Termination
Activating and Suspending an SSL Proxy List
Note
OL-5655-01
To set the amount of data in bytes that a given connection can buffer from the
•
server to the client, use the tx number2 keyword and variable. By default, the
buffer size is 65536. The buffer size can range from 16400 to 262144. For
example, to set the value to 131072, enter:
(config-ssl-proxy-list[ssl_list1])# ssl-server 20 tcp buffer-share
tx 131072
To reset the reset the buffer size to the default of 65536, enter:
(config-ssl-proxy-list[ssl_list1])# no ssl-server 20 tcp
buffer-share tx
Before you can activate an SSL proxy list, ensure that you have created at least
one virtual or back-end SSL server in the list (see the
Servers for an SSL Proxy List"
for SSL TCP Connections"
The CSS checks the SSL proxy list to verify that all of the necessary components
are configured, including verification of the certificate and key pair against each
other. If the verification fails, the certificate name is not accepted and the CSS
logs the error message
activate the SSL proxy list. You must either remove the configured key pair or
configure an appropriate certificate.
Use the active command to activate the new or modified SSL proxy list. For
example, enter:
(config-ssl-proxy-list[ssl_list1])# active
After you activate an SSL proxy list, you can add it to a service. See the
"Configuring a Service for SSL Termination"
No modifications to an SSL proxy list are permitted on an active list. Suspend the
list prior to making changes, and then reactivate the SSL proxy list once the
changes are complete. Once you have modified the SSL proxy list, suspend the
SSL service, reactivate the SSL proxy list, and then reactivate the SSL service.
To view the virtual or back-end SSL servers in a list, use the show ssl-proxy-list
(see
Chapter 7, Displaying SSL Configuration Information and
Activating and Suspending an SSL Proxy List
section or the
section earlier in this chapter).
Certificate and key pair do not match
Cisco Content Services Switch SSL Configuration Guide
"Configuring Virtual SSL
"Specifying the Nagle Algorithm
and does not
section later in this chapter.
Statistics).
4-47