Chapter 6
Configuring SSL Initiation
Configuring Back-End SSL Servers in an SSL Initiation Proxy List
Before you configure the CA certificate in an SSL initiation proxy list, you must
import the certificate on the CSS and then associate the certificate with a
filename. For information about importing a CA certificate, see the
"Importing or
Exporting Certificates and Private Keys"
section in
Chapter 3, Configuring SSL
Certificates and
Keys. For information about associating a certificate with a
filename, see the
"Associating Certificate and Private Key Files with Names"
section in
Chapter 3, Configuring SSL Certificates and
Keys.
To enable the SSL module (the client) to authenticate the SSL server, you must
configure at least one, with a maximum of four, CA certificates in the SSL
initiation proxy list. If you attempt to configure more than four CA certificates,
the CSS displays the following error message:
%% Max number of CA Certificates configured on server.
Use the cacert command to configure the CA certificates in the proxy list. The
syntax for this command is:
backend-server number cacert {name}
The name variable specifies the filename with which you have previously
associated the CA certificate. Enter a filename from 1 to 31 characters. The CA
certificate must already be loaded on the SCM. You can define a maximum of four
CA certificates for each SSL initiation proxy list. The CSS uses the CA
certificates to verify the server certificate in the order in which you configure the
CA certificates.
For example, to configure the mycert1 CA certificate in proxy list ssl_list1 for
SSL initiation server 1, enter:
(config-ssl-proxy-list[ssl_list1])# backend-server 1 cacert mycert1
To remove a CA certificate from an SSL proxy list, use the no form of the
command. For example, to remove the mycert1 CA certificate from the ssl_list1
proxy list for SSL initiation back-end server 1, enter:
(config-ssl-proxy-list[ssl_list1])# no backend-server 1 cacert mycert1
Cisco Content Services Switch SSL Configuration Guide
6-22
OL-5655-01