12-8
By default, the maximum number of cached sessions is 500 and the caching timeout time is 3,600
seconds.
The process of the session parameters negotiation and session establishment by using the SSL
handshake protocol is quite complicated. SSL allows reusing the negotiated session parameters to
establish sessions. Therefore, the SSL server needs to maintain information about existing sessions.
Note that the number of sessions and the time that the session information will be maintained are
limited:
z
If the number of sessions in the cache reaches the maximum, SSL rejects to cache new sessions.
z
If a session exists in the cache for a period equal to the caching timeout time, SSL will remove the
information of the session.
Related commands:
display ssl server-policy
.
Examples
# Set the caching timeout time to 4,000 seconds and the maximum number of cached sessions to 600.
<Sysname> system-view
[Sysname] ssl server-policy policy1
[Sysname-ssl-server-policy-policy1] session timeout 4000 cachesize 600
ssl client-policy
Syntax
ssl client-policy
policy-name
undo ssl client-policy
{
policy-name
|
all
}
View
System view
Default Level
2: System level
Parameters
policy-name:
SSL client policy name, a case-insensitive string of 1 to 16 characters, which cannot be
“a”, “al” and “all”.
all:
Specifies all SSL client policies.
Description
Use the
ssl client-policy
command to create an SSL policy and enter its view.
Use the
undo ssl client-policy
command to remove a specified or all SSL client policies.
Related commands:
display ssl client-policy
.
Examples
# Create an SSL client policy named policy1 and enter its view.
<Sysname> system-view
[Sysname] ssl client-policy policy1
[Sysname-ssl-client-policy-policy1]
Summary of Contents for E4510-48G
Page 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Page 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Page 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Page 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Page 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Page 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Page 914: ...5 17 Sysname reset oam ...
Page 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Page 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...