![IBM WebSphere XS40 Скачать руководство пользователя страница 260](http://html.mh-extra.com/html/ibm/websphere-xs40/websphere-xs40_command-reference-manual_607316260.webp)
Optionally, each cipher keyword can be preceded by the following
characters:
!
Permanently deletes the cipher from the list. Even if you explicitly
add the cipher to the list, it can never reappear in the list.
-
Deletes the cipher from the list. You can add this cipher again.
+
Moves the cipher to the end of the list. The
+
character moves
existing ciphers, it does not add them.
If none of these characters is present, the string is interpreted as a list of
ciphers to be appended to the current list. If the list includes a cipher that
is already in the list, that cipher is ignored. That is, existing ciphers are not
moved to the end of the list.
Additionally, the cipher string can contain the
@STRENGTH
keyword at any
point to sort the cipher list in order of encryption algorithm key length.
options
options-mask
Optionally enables various SSL options for the Crypto Profile. Use the
string or specify a hexadecimal representation of a 32-bit mask string that
identifies specific supported SSL options. Table 6 lists the available options.
Table 6. SSL options as string and hexadecimal representation
String value
Hexadecimal
representation
Description
OpenSSL-default
0x000FFFFF
Default value
Disable-SSLv2
0x01000000
Disallows the use of SSL
version 2
Disable-SSLv3
0x02000000
Disallows the use of SSL
version 3
Disable-TLSv1
0x04000000
Disallows the use of TLS
version 3
When using hexadecimal representation, use a logical
OR
to modify the
behavior during the SSL handshake. When using the string value, use a
+
character to join values. For example, to disallow both SSL version 2 and
TLS version 1, enter one following values:
Hexadecimal
0x05000000
String
Disable-SSLv2+DisableTLSv1
Guidelines
A Crypto Profile defines a level of SSL service. When you create an SSL Proxy
Profile with the
sslproxy
command, you assign a Crypto Profile to the SSL Proxy
Profile.
Before creating a Crypto Profile to use with an SSL server, use the
certificate
command with the
key
and
idcred
commands to create an Identification
Credentials. This set of credentials consists of a certificate, which contains a public
key, and the corresponding private key.
A Crypto Profile optionally uses a Validation Credentials to validate certificates
that are received from remote SSL peers.
234
Command Reference
Содержание WebSphere XS40
Страница 1: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Страница 2: ......
Страница 3: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Страница 44: ...18 Command Reference ...
Страница 194: ...168 Command Reference ...
Страница 198: ...172 Command Reference ...
Страница 206: ...180 Command Reference ...
Страница 210: ...184 Command Reference ...
Страница 222: ...196 Command Reference ...
Страница 232: ...206 Command Reference ...
Страница 238: ...212 Command Reference ...
Страница 268: ...242 Command Reference ...
Страница 272: ...246 Command Reference ...
Страница 276: ...250 Command Reference ...
Страница 288: ...262 Command Reference ...
Страница 292: ...266 Command Reference ...
Страница 298: ...272 Command Reference ...
Страница 320: ...294 Command Reference ...
Страница 322: ...296 Command Reference ...
Страница 340: ...314 Command Reference ...
Страница 344: ...318 Command Reference ...
Страница 352: ...326 Command Reference ...
Страница 360: ...334 Command Reference ...
Страница 368: ...342 Command Reference ...
Страница 376: ...350 Command Reference ...
Страница 386: ...360 Command Reference ...
Страница 392: ...366 Command Reference ...
Страница 396: ...370 Command Reference ...
Страница 402: ...376 Command Reference ...
Страница 404: ...378 Command Reference ...
Страница 408: ...382 Command Reference ...
Страница 446: ...420 Command Reference ...
Страница 450: ...424 Command Reference ...
Страница 456: ...430 Command Reference ...
Страница 458: ... message type Extranet Message type configuration mode no message matching TFDef2 432 Command Reference ...
Страница 520: ...494 Command Reference ...
Страница 536: ...510 Command Reference ...
Страница 550: ...524 Command Reference ...
Страница 584: ...558 Command Reference ...
Страница 600: ...574 Command Reference ...
Страница 605: ... timeout 500 Chapter 63 RADIUS configuration mode 579 ...
Страница 606: ...580 Command Reference ...
Страница 638: ...v Allow access by the admin account to all access methods restrict admin off 612 Command Reference ...
Страница 650: ...624 Command Reference ...
Страница 667: ...v Specifies support for SNMP Version 2c the default state version 2c Chapter 72 SNMP Settings configuration mode 641 ...
Страница 668: ...642 Command Reference ...
Страница 704: ...678 Command Reference ...
Страница 714: ...688 Command Reference ...
Страница 726: ...700 Command Reference ...
Страница 734: ...708 Command Reference ...
Страница 752: ...726 Command Reference ...
Страница 756: ...730 Command Reference ...
Страница 804: ...778 Command Reference ...
Страница 880: ...854 Command Reference ...
Страница 892: ...866 Command Reference ...
Страница 912: ...886 Command Reference ...
Страница 918: ...892 Command Reference ...
Страница 940: ...914 Command Reference ...
Страница 946: ...920 Command Reference ...
Страница 974: ...948 Command Reference ...
Страница 1004: ...978 Command Reference ...
Страница 1030: ...1004 Command Reference ...
Страница 1032: ...1006 Command Reference ...
Страница 1038: ...Other company product and service names may be trademarks or service marks of others 1012 Command Reference ...
Страница 1065: ......
Страница 1066: ... Printed in USA ...