<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: managing SSL certifications in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/managing-ssl-certifications/m-p/1028937#M20439</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought the same thing but I wasn't sure and I would know your opinion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Apr 2008 12:10:30 GMT</pubDate>
    <dc:creator>gpangallo</dc:creator>
    <dc:date>2008-04-10T12:10:30Z</dc:date>
    <item>
      <title>managing SSL certifications</title>
      <link>https://community.cisco.com/t5/application-networking/managing-ssl-certifications/m-p/1028935#M20437</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured on the CSS content rules for SSL traffic without using the SSL module and SSL proxy list but I noticed some issues regarding to the correct acquisition of the SSL certificate from the client side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know if configuring the CSS as transparent Gateway for SSL can create those issues. &lt;/P&gt;&lt;P&gt;Moreover, how could I check it on CSS? &lt;/P&gt;&lt;P&gt;The CSS configuration is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;content HTTPS &lt;/P&gt;&lt;P&gt;    port 3453 &lt;/P&gt;&lt;P&gt;    protocol tcp &lt;/P&gt;&lt;P&gt;    vip address 10.1xx.x.x &lt;/P&gt;&lt;P&gt;    add service server_SSL_1 &lt;/P&gt;&lt;P&gt;    add service server_SSL_2 &lt;/P&gt;&lt;P&gt;    advanced-balance ssl &lt;/P&gt;&lt;P&gt;    application ssl &lt;/P&gt;&lt;P&gt;    active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service server_SSL_1 &lt;/P&gt;&lt;P&gt;  keepalive port 3456&lt;/P&gt;&lt;P&gt;  ip address 10.1xx.x.y&lt;/P&gt;&lt;P&gt;  port 3456&lt;/P&gt;&lt;P&gt;  active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service server_SSL_2 &lt;/P&gt;&lt;P&gt;  keepalive port 3456 &lt;/P&gt;&lt;P&gt;  ip address 10.1xx.x.z &lt;/P&gt;&lt;P&gt;  port 3456&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2008 15:17:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/managing-ssl-certifications/m-p/1028935#M20437</guid>
      <dc:creator>gpangallo</dc:creator>
      <dc:date>2008-04-09T15:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: managing SSL certifications</title>
      <link>https://community.cisco.com/t5/application-networking/managing-ssl-certifications/m-p/1028936#M20438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not know any issue about acquisition of client cert.&lt;/P&gt;&lt;P&gt;Normally the CSS will just wait for the client ssl hello to detect the sslid but it will then pass all the information transparently to the server and the ssl handshake will continue between client and server.&lt;/P&gt;&lt;P&gt;Get a sniffer trace on the server to see what is going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Apr 2008 10:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/managing-ssl-certifications/m-p/1028936#M20438</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2008-04-10T10:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: managing SSL certifications</title>
      <link>https://community.cisco.com/t5/application-networking/managing-ssl-certifications/m-p/1028937#M20439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought the same thing but I wasn't sure and I would know your opinion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Apr 2008 12:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/managing-ssl-certifications/m-p/1028937#M20439</guid>
      <dc:creator>gpangallo</dc:creator>
      <dc:date>2008-04-10T12:10:30Z</dc:date>
    </item>
  </channel>
</rss>

