![HP FlexNetwork MSR Series Command Reference Manual Download Page 662](http://html.mh-extra.com/html/hp/flexnetwork-msr-series/flexnetwork-msr-series_command-reference-manual_163078662.webp)
644
SSL commands
The device supports the FIPS mode that complies with NIST FIPS 140-2 requirements. Support for
features, commands, and parameters might differ in FIPS mode and non-FIPS mode. For more
information about FIPS mode, see
Security Configuration Guide
.
certificate-chain-sending enable
Use
certificate-chain-sending enable
to enable the SSL server to send the complete certificate
chain to the client during SSL negotiation.
Use
undo certificate-chain-sending enable
to restore the default.
Syntax
certificate-chain-sending enable
undo certificate-chain-sending enable
Default
During SSL negotiation, the SSL server sends the server certificate rather than the complete
certificate chain to the client.
Views
SSL server policy view
Predefined user roles
network-admin
Usage guidelines
This feature causes additional overheads in the SSL negotiation process. Enable it only when the
SSL client do not have the complete certificate chain to verify the server certificate.
Examples
<Sysname> system-view
[Sysname] ssl server-policy policy1
[Sysname-ssl-server-policy-policy1] certificate-chain-sending enable
ciphersuite
Use
ciphersuite
to specify the cipher suites supported by an SSL server policy.
Use
undo ciphersuite
to restore the default.
Syntax
In non-FIPS mode:
ciphersuite
{
dhe_rsa_aes_128_cbc_sha
|
dhe_rsa_aes_256_cbc_sha
|
exp_rsa_des_cbc_sha
|
exp_rsa_rc2_md5
|
exp_rsa_rc4_md5
|
rsa_3des_ede_cbc_sha
|
rsa_aes_128_cbc_sha
|
rsa_aes_256_cbc_sha
|
rsa_des_cbc_sha
|
rsa_rc4_128_md5
|
rsa_rc4_128_sha
} *
undo ciphersuite
In FIPS mode:
ciphersuite
{
rsa_aes_128_cbc_sha
|
rsa_aes_256_cbc_sha
} *
undo ciphersuite
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...