Appendix E: Using Certificates in HTTPS Clusters
290
Equalizer Installation and Administration Guide
For example, SSLv2 encryption is supported by default. If your servers are required to support medium and high
encryption using SSLv3
only
, you can add “
!SSLv2
” to
cipher suite
. For example, the following cipher suite string
will cause all non-SSLv3 client requests to be refused:
AES128-SHA:DES-CBC3-SHA:RC4-SHA:RC4-MD5:AES256-SHA:!SSLv2:+SSLv3
The
cipher suite
field requires a string in the format described in the OpenSSL cipher suite documentation, at:
http://www.openssl.org/docs/apps/ciphers.html
The tables in the following sections list the cipher suites
supported by Equalizer. Also see the discussion of the
cluster parameter “
cipher suite
” on page 120.
No Xcel (Software) and Xcel II Cipher Suites
The following cipher suites are supported by the base Equalizer software and by the Xcel II (newer generation) SSL
Acceleration Hardware:
Xcel I Cipher Suites
The following cipher suites are supported by the older generation Xcel I SSL Acceleration Hardware.
OpenSSL Cipher Suite Name
TLS/SSL Cipher Suite Names
AES128-SHA
TLS_RSA_WITH_AES_128_CBC_SHA
DES-CBC3-SHA
TLS_RSA_WITH_3DES_EDE_CBC_SHA
SSL_RSA_WITH_3DES_EDE_CBC_SHA
RC4-SHA
TLS_RSA_WITH_RC4_128_SHA
SSL_RSA_WITH_RC4_128_SHA
RC4-MD5
TLS_RSA_WITH_RC4_128_MD5
SSL_RSA_WITH_RC4_128_MD5
AES256-SHA
TLS_RSA_WITH_AES_256_CBC_SHA
The cipher suites below are supported but are not recommended.
(In earlier
releases, the EXP-RC4-MD5 ciphers were included by default in
cipher suite
for older browsers
that only support 40-bit encryption. If some clients for your web services support only 40-bit
encryption, then add EXP-RC4-MD5 to the
cipher suite
list.)
EXP-RC4-MD5
TLS_RSA_EXPORT_WITH_RC4_40_MD5
SSL_RSA_EXPORT_WITH_RC4_40_MD5
SSL_CK_RC4_128_EXPORT40_WITH_MD5
OpenSSL Cipher Suite Name
TLS/SSL Cipher Suite Names
DES-CBC3-SHA
TLS_RSA_WITH_3DES_EDE_CBC_SHA
SSL_RSA_WITH_3DES_EDE_CBC_SHA
RC4-SHA
TLS_RSA_WITH_RC4_128_SHA
SSL_RSA_WITH_RC4_128_SH
Содержание E350GX
Страница 18: ...Chapter Preface 18 Equalizer Installation and Administration Guide ...
Страница 38: ...Chapter 1 Equalizer Overview 38 Equalizer Installation and Administration Guide ...
Страница 50: ...Chapter 2 Installing and Configuring Equalizer Hardware 50 Equalizer Installation and Administration Guide ...
Страница 62: ...Chapter 3 Using the Administration Interface 62 Equalizer Installation and Administration Guide ...
Страница 80: ...Chapter 4 Equalizer Network Configuration 80 Equalizer Installation and Administration Guide ...
Страница 110: ...Chapter 5 Configuring Equalizer Operation 110 Equalizer Installation and Administration Guide ...
Страница 208: ...Chapter 7 Monitoring Equalizer Operation 208 Equalizer Installation and Administration Guide ...
Страница 240: ...Chapter 8 Using Match Rules 238 Equalizer Installation and Administration Guide ...
Страница 258: ...Chapter 9 Administering GeoClusters 254 Equalizer Installation and Administration Guide Envoy Configuration Worksheet ...
Страница 262: ...Appendix A Server Agent Probes 258 Equalizer Installation and Administration Guide ...
Страница 274: ...Appendix B Timeout Configuration 270 Equalizer Installation and Administration Guide ...
Страница 280: ...Appendix D Regular Expression Format 276 Equalizer Installation and Administration Guide ...
Страница 296: ...Appendix E Using Certificates in HTTPS Clusters 292 Equalizer Installation and Administration Guide ...
Страница 310: ...Appendix F Equalizer VLB 306 Equalizer Installation and Administration Guide ...
Страница 318: ...Appendix G Troubleshooting 314 Equalizer Installation and Administration Guide ...