Configuring the Server’s Security Preferences
Chapter
14
Managing CMS Keys and Certificates
483
Figure 14-1
SSL version 2.0 and 3.0 cipher suites supported (in the domestic version)
You can choose ciphers from the SSL 2.0 protocol, as well as from SSL 3.0. To
specify which ciphers your server can use, check them in the list of ciphers to
enable them. Unless you have a compelling reason not to use a specific cipher, you
should check them all, except as noted in the warning that follows. For a detailed
description of ciphers, see "Ciphers Used with SSL" in Appendix E of Managing
Servers with Netscape Console.
Previous US law prohibited the export of software with strong encryption, so most
browsers still in use outside of the US and Canada do not support 128-bit
encryption. Disabling all 40-bit ciphers will ensure that all connections use
higher-grade security, but will prevent access to your service to many users outside
of the US and Canada.
CAUTION
You might not want to check the options that say “No Encryption,
only MD5 message authentication” and “No Encryption, only
Fortezza and SHA message authentication.” The reason for this is, if
no other ciphers are available on the client side, the server will use
these and no encryption will occur.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...