Chapter 6: Administering Virtual Clusters
120
Equalizer Installation and Administration Guide
•
upload an SSL certificate that clients will use to validate a connection to an HTTPS cluster (a
cluster
certificate)
•
upload an SSL certificate for Equalizer to use to validate clients that request connections to HTTPS clusters
(a
client
certificate)
See “Using Certificates in HTTPS Clusters” on page 278 for more information.
Layer 7 Security > SSL Tab (HTTPS only)
The
Security > SSL
tab allows you to configure various options that are specific to HTTPS connections.
cipher suite
Lists the supported cipher suites for incoming HTTPS requests. If a
client request comes into Equalizer that does not use a cipher in this
list, the connection is refused. Please see “Configuring Cipher Suites” on
page 289.
session cache timeout
The number of seconds that Equalizer waits before disposing of an SSL
session cache entry.
session cache kbytes
The maximum amount of memory in kilobytes allotted to an SSL session
cache.
client verification depth
The depth to which certificate checking is done on the client certificate
chain. The default of 2 indicates that the client certificate (level 0) and
two levels above it (levels 1 and 2) are checked; any certificates above
level 2 in the chain are ignored. You should only need to increase this
value if the Certificate Authority that issued your certificate provided
you with more than 2 chained certificates in addition to your client
certificate. See Appendix E, ”Using Certificates in HTTPS Clusters” on
page 277.
certify client
Indicates whether the server asks the client for a client certificate when
a client request is received. The connection will succeed even if the
client does not provide a certificate; but, if one is provided by the client
it will be validated. See Appendix E, ”Using Certificates in HTTPS
Clusters” on page 277.
require certificate
Indicates whether the server requires a client certificate when a client
request is received.
If
the client does not provide a certificate, the
connection is refused. See Appendix E, ”Using Certificates in HTTPS
Clusters” on page 277.
verify once
Indicates that the server will verify certificates only on the first client
request, even if SSL is renegotiated. See Appendix E, ”Using Certificates
in HTTPS Clusters” on page 277.
ssl unclean shutdown
Should be enabled if you cannot access pages while trying to maintain
HTTPS persistent connections over HTTP/1.1. This problem especially
applies to connections between Internet Explorer and Apache Servers
and usually occurs intermittently.
Summary of Contents for E350GX
Page 18: ...Chapter Preface 18 Equalizer Installation and Administration Guide ...
Page 38: ...Chapter 1 Equalizer Overview 38 Equalizer Installation and Administration Guide ...
Page 80: ...Chapter 4 Equalizer Network Configuration 80 Equalizer Installation and Administration Guide ...
Page 110: ...Chapter 5 Configuring Equalizer Operation 110 Equalizer Installation and Administration Guide ...
Page 208: ...Chapter 7 Monitoring Equalizer Operation 208 Equalizer Installation and Administration Guide ...
Page 240: ...Chapter 8 Using Match Rules 238 Equalizer Installation and Administration Guide ...
Page 262: ...Appendix A Server Agent Probes 258 Equalizer Installation and Administration Guide ...
Page 274: ...Appendix B Timeout Configuration 270 Equalizer Installation and Administration Guide ...
Page 280: ...Appendix D Regular Expression Format 276 Equalizer Installation and Administration Guide ...
Page 310: ...Appendix F Equalizer VLB 306 Equalizer Installation and Administration Guide ...
Page 318: ...Appendix G Troubleshooting 314 Equalizer Installation and Administration Guide ...