Chapter 3 Commands Specific to the Content Switching Module with SSL

ssl-proxy pki

ssl-proxy pki

To configure and define the PKI implementation on the Content Switching Module with SSL, use the ssl-proxy pki command.Use the no form of this command to disable the logging and clear the memory.

ssl-proxy pki {{authenticate {timeout seconds}} {cache {{size entries} {timeout minutes}}}

{certificate {check-expiring {interval hours}}} history}

 

 

no ssl-proxy pki {authenticate cache certificate history}

 

 

 

 

Syntax Description

 

authenticate

Configures the certificate authentication and authorization.

 

 

 

 

 

 

timeout seconds

Specifies the timeout in seconds for each request; valid values are from 1 to

 

 

 

600 seconds.

 

 

 

 

 

 

cache

Configures the peer-certificate cache.

 

 

 

 

 

 

size entries

Specifies the maximum number of cache entries; valid values are from 0 to

 

 

 

5000 entries.

 

 

 

 

 

 

timeout minutes

Specifies the aging timeout value of entries; valid values are from 1 to 600

 

 

 

minutes.

 

 

 

 

 

 

certificate

Configures the check-expiring interval.

 

 

 

 

 

 

check-expiring

Specifies the check-expiring interval; valid values are from 0 to 720 hours.

 

 

interval hours

 

 

 

 

 

 

 

 

history

Key and certificate history.

 

 

 

 

 

 

 

 

Defaults

 

The default settings are as follows:

 

 

timeout seconds180 seconds

 

 

size entries0entries

 

 

 

timeout minutes15 minutes

 

 

interval hours0hours, do not check

 

 

 

 

 

Command Modes

 

Global configuration

 

 

 

 

 

 

Command History

 

Release

Modification

 

 

 

 

 

 

Cisco IOS Release

Support for this command was introduced on the Catalyst 6500 series

 

 

12.1(13)E and

switches.

 

 

SSL Services Module

 

 

 

Release 1.1(1)

 

 

 

 

 

 

 

SSL Services Module This command was changed to add the following keywords:

 

 

Release 2.1(1)

authenticate

 

 

 

 

 

 

cache

 

 

 

certificate

CSM-S release 1.1(1) This command was introduced.

Catalyst 6500 Series Switch Content Switching Module with SSL Command Reference

3-52

OL-7029-01

 

 

Page 274
Image 274
Cisco Systems OL-7029-01 manual Ssl-proxy pki