ParameterDescription

SyntaxInteger

Example

nssslsessiontimeout: 5

2.3.3.2 nssslclientauth

This attribute sets how clients may use certificates to authenticate to the Directory Server for SSL connections. If this attribute is set to required, which enforces clients to use authentication certification, you cannot set the Console to require SSL. Certificate-based authentication is not supported with the Console

The server has to be restarted for changes to this attribute to go into effect.

Parameter

Description

 

Entry DN

cn=encryption,cn=config

 

 

Valid Values

Any of the following:

 

off

Means disallow certificate-based authentication

 

allowed

Means clients may use certificates or other forms of authentication

 

required Means clients must use certificates for authentication

 

 

 

Default Value

allowed

 

 

 

Syntax

DirectoryString

 

 

Example

nssslclientauth: allowed

 

 

 

2.3.3.3 nsSSL2

Supports SSL version 2. SSLv2 is deprecated, and HP strongly discourages using it. The server has to be restarted for changes to this attribute to go into effect.

Parameter

Description

Entry DN

cn=encryption,cn=config

 

 

Valid Values

on or off

 

 

Default Value

off

 

 

Syntax

DirectoryString

 

 

Example

nsssl2: off

 

 

2.3.3.4 nsSSL3

Supports SSL version 3.

The server has to be restarted for changes to this attribute to go into effect.

Parameter

Description

Entry DN

cn=encryption,cn=config

 

 

Valid Values

on or off

 

 

Default Value

on

 

 

Syntax

DirectoryString

 

 

Example

nsssl3: on

 

 

74 Core server configuration reference