Verifying Server certificates
Verifying server certificates is mandatory in the TLS protocol.
As a result, all TLS-enabled applications require certificate verification, including Syslog servers. The system checks the Server certificates
against installed CA certificates.
NOTE:
As part of the certificate verification, the hostname or IP address of the server is verified against the hostname or IP
address specified in the application. For example, when using SYSLOG over TLS, the hostname or IP address specified in the
logging syslog-server secure port port-number
command is compared against the SubjectAltName or Common
Name field in the server certificate.
Verifying Client Certificates
Verifying client certificates is optional in the TLS protocol and is not explicitly required by Common Criteria.
However, TLS-protected Syslog and RADIUS protocols mandate that certificate-based mutual authentication be performed.
Event logging
The system logs the following events:
•
A CA certificate is installed or deleted.
•
A self-signed certificate and private key are generated.
•
An existing host certificate, a private key, or both are deleted.
•
A host certificate is installed successfully.
•
An installed certificate (host certificate or CA certificate) is within seven days of expiration. This alert is repeated periodically.
•
An OCSP request is not answered with an OCSP response.
•
A secure session negotiation fails due to invalid, expired, or revoked certificate.
1146
X.509v3
Содержание S4048T-ON
Страница 1: ...Dell Configuration Guide for the S4048 ON System 9 11 2 1 ...
Страница 148: ...Figure 10 BFD Three Way Handshake State Changes 148 Bidirectional Forwarding Detection BFD ...
Страница 251: ...Dell Control Plane Policing CoPP 251 ...
Страница 363: ... RPM Synchronization GARP VLAN Registration Protocol GVRP 363 ...
Страница 511: ...Figure 64 Inspecting the LAG Configuration Link Aggregation Control Protocol LACP 511 ...
Страница 512: ...Figure 65 Inspecting Configuration of LAG 10 on ALPHA 512 Link Aggregation Control Protocol LACP ...
Страница 515: ...Figure 67 Inspecting a LAG Port on BRAVO Using the show interface Command Link Aggregation Control Protocol LACP 515 ...
Страница 516: ...Figure 68 Inspecting LAG 10 Using the show interfaces port channel Command 516 Link Aggregation Control Protocol LACP ...
Страница 558: ...Figure 84 Configuring Interfaces for MSDP 558 Multicast Source Discovery Protocol MSDP ...
Страница 559: ...Figure 85 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 559 ...
Страница 560: ...Figure 86 Configuring PIM in Multiple Routing Domains 560 Multicast Source Discovery Protocol MSDP ...
Страница 564: ...Figure 88 MSDP Default Peer Scenario 2 564 Multicast Source Discovery Protocol MSDP ...
Страница 565: ...Figure 89 MSDP Default Peer Scenario 3 Multicast Source Discovery Protocol MSDP 565 ...
Страница 729: ...protocol spanning tree pvst no disable vlan 300 bridge priority 4096 Per VLAN Spanning Tree Plus PVST 729 ...
Страница 841: ...Figure 115 Single and Double Tag TPID Match Service Provider Bridging 841 ...
Страница 842: ...Figure 116 Single and Double Tag First byte TPID Match 842 Service Provider Bridging ...