<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSS: &amp;quot;ssl-server 10 rsacert&amp;quot; command was deleted during boot in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155011#M23920</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;-----start page 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure Secure Socket Layer (SSL) Service and Content Rules Once the SSL proxy list is activated, a service and content rule need to be configured to allow the CSS to send SSL traffic to the SSL module. This table provides an overview of the steps required to create an SSL service for a virtual SSL server, including adding the SSL proxy list to the service and creating an SSL content rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create an SSL service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config)# service ssl_serv1Create service , [y/n]: y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# type ssl-accel &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# slot 2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# keepalive type none &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# add ssl-proxy-list ssl_list1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create an SSL content rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config)# owner ssl_owner &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create owner , [y/n]: y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner[ssl_owner])# content ssl_rule1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create content , [y/n]: y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[ssl-rule1]# vip address 192.168.3.6 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[ssl-rule1]# port 443 CSS11500(config-owner-content[ssl_rule1])# add service ssl_serv1 CSS11500(config-owner-content[ssl_rule1])# active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a clear text content rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner[ssl_owner])# content decrypted_www Create content , [y/n]: y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www]# vip address 192.168.11.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www]# port 80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www])# add service linux_http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www])# add service win2k_http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www])# active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point, client HTTPS traffic can be sent to the CSS at 192.168.3.6:443. The CSS decrypts the HTTPS traffic, converting it to HTTP. The CSS then chooses a service and sends the HTTP traffic to a HTTP Web server. The following is a working CSS configuration &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the following URL for Requesting and Installing a Server Certificate on the CSS11500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_configuration_example09186a00801ffdcb.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_configuration_example09186a00801ffdcb.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sachin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Apr 2009 22:35:59 GMT</pubDate>
    <dc:creator>sachinga.hcl</dc:creator>
    <dc:date>2009-04-08T22:35:59Z</dc:date>
    <item>
      <title>CSS: "ssl-server 10 rsacert" command was deleted during boot up</title>
      <link>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155009#M23918</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After rebooting both Pri/Sec CSSs, "ssl-server 10 rsacert" command under "ssl-proxy-list" was deleted on both CSSs.&lt;/P&gt;&lt;P&gt;Because same symptom occurred on both CSSs, I'd like to explain the detail of the problem about one CSS(Pri CSS).&lt;/P&gt;&lt;P&gt;The following was the config just after rebooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ssl associate cert key1-09.crt key1-09.crt &lt;/P&gt;&lt;P&gt;  ssl associate rsakey key1-06.pem key1-06.pem &lt;/P&gt;&lt;P&gt;ssl-proxy-list SSL-LIST &lt;/P&gt;&lt;P&gt;  ssl-server 10 &lt;/P&gt;&lt;P&gt;  ssl-server 10 vip address 172.16.3.32 &lt;/P&gt;&lt;P&gt;  ssl-server 10 cipher rsa-with-rc4-128-sha 172.16.3.32 80 &lt;/P&gt;&lt;P&gt;  ssl-server 10 rsakey key1-06.pem &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"ssl-server 10 rsacert key1-09.crt" didn't exist.&lt;/P&gt;&lt;P&gt;So the problem was resolved by just adding "ssl-server 10 rsacert key1-09.crt".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ssl associate cert key1-09.crt key1-09.crt &lt;/P&gt;&lt;P&gt;  ssl associate rsakey key1-06.pem key1-06.pem &lt;/P&gt;&lt;P&gt;ssl-proxy-list SSL-LIST &lt;/P&gt;&lt;P&gt;  ssl-server 10 &lt;/P&gt;&lt;P&gt;  ssl-server 10 vip address 172.16.3.32 &lt;/P&gt;&lt;P&gt;  ssl-server 10 cipher rsa-with-rc4-128-sha 172.16.3.32 80 &lt;/P&gt;&lt;P&gt;  ssl-server 10 rsakey key1-06.pem &lt;/P&gt;&lt;P&gt;  ssl-server 10 rsacert key1-09.crt&lt;/P&gt;&lt;P&gt;  active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to go back to explain the problem before adding "ssl-server 10 rsacert key1-09.crt".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After rebooting, I found the following error on CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#sh log startup-errors tail 100&lt;/P&gt;&lt;P&gt;57.  ssl-server 10 rsacert key1-09.crt&lt;/P&gt;&lt;P&gt;%% SSL Proxy List ssl-server does not exist&lt;/P&gt;&lt;P&gt;58.  active&lt;/P&gt;&lt;P&gt;%% SSL Proxy Lists must have ssl-servers or backend-servers before activation&lt;/P&gt;&lt;P&gt;90.  active&lt;/P&gt;&lt;P&gt;%% No active ssl-lists on service, service not activated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show ssl flows&lt;/P&gt;&lt;P&gt;SSL Acceleration Flows for module 2&lt;/P&gt;&lt;P&gt;-- No active VIPs found for module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certificate was surely existed on CSS even after rebooting, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show ssl files&lt;/P&gt;&lt;P&gt; File Name                File Type File Size &lt;/P&gt;&lt;P&gt; ----------------         --------- ------------&lt;/P&gt;&lt;P&gt; key1-06.pem   PEM        887       &lt;/P&gt;&lt;P&gt; key1-09.crt   PEM        1914    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found strange thing might be caused this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer updated the certificate on CSS on February with the following procedure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1: copied new certificate into CSS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2: confirmed config before upgrading&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ssl associate rsakey key1-06.pem key1-06.pem&lt;/P&gt;&lt;P&gt;  ssl associate cert key1-07.crt key1-07.crt&lt;/P&gt;&lt;P&gt;ssl-proxy-list SSL-LIST&lt;/P&gt;&lt;P&gt;  ssl-server 10&lt;/P&gt;&lt;P&gt;  ssl-server 10 vip address 172.16.3.32&lt;/P&gt;&lt;P&gt;  ssl-server 10 cipher rsa-with-rc4-128-sha 172.16.3.32 80&lt;/P&gt;&lt;P&gt;  ssl-server 10 rsakey key1-06.pem&lt;/P&gt;&lt;P&gt;  ssl-server 10 rsacert key1-07.crt&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3: upgraded the certificate from "key1-07.crt" to "key1-09.crt"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl associate cert key1-09.crt key1-09.crt&lt;/P&gt;&lt;P&gt;no ssl associate cert key1-07.crt&lt;/P&gt;&lt;P&gt;ssl-proxy-list SSL-LIST&lt;/P&gt;&lt;P&gt;suspend&lt;/P&gt;&lt;P&gt;no ssl-server 10 rsacert&lt;/P&gt;&lt;P&gt;ssl-server 10 rsacert key1-09.crt&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;(exited from config mode, wr mem to save)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4: confirmed config after upgrading&lt;/P&gt;&lt;P&gt;  ssl associate cert key1-09.crt key1-09.crt&lt;/P&gt;&lt;P&gt;  ssl associate rsakey key1-06.pem key1-06.pem&lt;/P&gt;&lt;P&gt;ssl-proxy-list SSL-LIST&lt;/P&gt;&lt;P&gt;  ssl-server 10 rsacert key1-09.crt&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;  ssl-server 10&lt;/P&gt;&lt;P&gt;  ssl-server 10 vip address 172.16.3.32&lt;/P&gt;&lt;P&gt;  ssl-server 10 cipher rsa-with-rc4-128-sha 172.16.3.32 80&lt;/P&gt;&lt;P&gt;  ssl-server 10 rsakey key1-06.pem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the cause of this problem was that "ssl-server 10 rsacert key1-09.crt" was on the top of ssl-proxy-list (4:) and the following &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally "ssl-server 10 vip address 172.16.3.32" must be loaded before loading "ssl-server 10 rsacert key1-09.crt".&lt;/P&gt;&lt;P&gt;But in this case, CSS might load "ssl-server 10 rsacert key1-09.crt" first before loading "ssl-server 10 vip address 172.16.3.32".&lt;/P&gt;&lt;P&gt;Therefore, CSS logged the following error and then CSS might delete "ssl-server 10 rsacert key1-09.crt".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSL Acceleration Flows for module 2&lt;/P&gt;&lt;P&gt;-- No active VIPs found for module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you experienced same problem?&lt;/P&gt;&lt;P&gt;Does CSS delete "ssl-server 10 rsacert" from its config if "ssl-server 10 vip address" hadn't loaded first?&lt;/P&gt;&lt;P&gt;Did the upgrading procedure of certificate make mistake?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think CSS version 7.50.303 no longer supported by TAC and could not find any bug related it.&lt;/P&gt;&lt;P&gt;So I posted it to give me any information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shin&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2009 08:53:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155009#M23918</guid>
      <dc:creator>snakayama</dc:creator>
      <dc:date>2009-04-06T08:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: CSS: "ssl-server 10 rsacert" command was deleted during boot</title>
      <link>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155010#M23919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kindly Use following procedure to add certificate:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://crystaltech.xrampsecurity.com/support.php?s=csr&amp;amp;sr=22" target="_blank"&gt;https://crystaltech.xrampsecurity.com/support.php?s=csr&amp;amp;sr=22&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco CSS 11500&lt;/P&gt;&lt;P&gt;Installing your Certificate on Cisco CSS 11500 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once the CSR has been signed by a CA, it is now called a Certificate. The Certificate file must be imported to the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Import Chained Certificate File&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue the copy ssl command to facilitate the import or export of certificates and private keys from or to the CSS. The CSS stores all imported files in a secure location on the CSS. This command is available only in SuperUser mode. For example, to import the mychainedrsacert.pem certificate from a remote server to the CSS, type the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500# copy ssl sftp ssl_record import mychainedrsacert.pem PEM ï¿½passwd123ï¿½&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connecting Completed successfully &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: XRamp certificates are issued using a .cer format. .pem, .cer, and .crt extensions can be interchanged, as they are the same type of file. &lt;/P&gt;&lt;P&gt;Associate the Certificate File&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue the ssl associate cert command to associate a certificate name to the imported certificate. For example, to associate the certificate name mychainedrsacert1 to the imported certificate file mychainedrsacert.pem, type the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config)# ssl associate cert mychainedrsacert1 mychainedrsacert.pem &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure the SSL Proxy List&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue the ssl-proxy-list command to create an SSL proxy list. An SSL proxy list is a group of related virtual or backend SSL servers that are associated with an SSL service. The SSL proxy list contains all the configuration information for each virtual SSL Server. This includes the SSL Server creation, certificates and corresponding SSL key pair, Virtual IP (VIP) address and port, SSL ciphers supported, and other SSL options. For example, to create the ssl-proxy-list ssl_list1, type the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config)# ssl-proxy-list ssl_list1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create ssl-list , [y/n]: y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you create an SSL proxy list, the CLI enters you into the ssl-proxy-list configuration mode. Configure your SSL server as shown below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(ssl-proxy-list[ssl_list1])# ssl-server 20 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(ssl-proxy-list[ssl_list1])# ssl-server 20 vip address 192.168.3.6 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(ssl-proxy-list[ssl_list1])# ssl-server 20 rsacert mychainedrsacert1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(ssl-proxy-list[ssl_list1])# ssl-server 20 rsakey myrsakey1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(ssl-proxy-list[ssl_list1])# ssl-server 20 cipher rsa-export-with-rc4-40-md5 192.168.11.2 80 5 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(ssl-proxy-list[ssl_list1])# active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                            ......end PAGE 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2009 22:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155010#M23919</guid>
      <dc:creator>sachinga.hcl</dc:creator>
      <dc:date>2009-04-08T22:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: CSS: "ssl-server 10 rsacert" command was deleted during boot</title>
      <link>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155011#M23920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;-----start page 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure Secure Socket Layer (SSL) Service and Content Rules Once the SSL proxy list is activated, a service and content rule need to be configured to allow the CSS to send SSL traffic to the SSL module. This table provides an overview of the steps required to create an SSL service for a virtual SSL server, including adding the SSL proxy list to the service and creating an SSL content rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create an SSL service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config)# service ssl_serv1Create service , [y/n]: y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# type ssl-accel &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# slot 2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# keepalive type none &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# add ssl-proxy-list ssl_list1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-service[ssl_serv1])# active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create an SSL content rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config)# owner ssl_owner &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create owner , [y/n]: y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner[ssl_owner])# content ssl_rule1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create content , [y/n]: y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[ssl-rule1]# vip address 192.168.3.6 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[ssl-rule1]# port 443 CSS11500(config-owner-content[ssl_rule1])# add service ssl_serv1 CSS11500(config-owner-content[ssl_rule1])# active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a clear text content rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner[ssl_owner])# content decrypted_www Create content , [y/n]: y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www]# vip address 192.168.11.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www]# port 80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www])# add service linux_http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www])# add service win2k_http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11500(config-owner-content[decrypted_www])# active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point, client HTTPS traffic can be sent to the CSS at 192.168.3.6:443. The CSS decrypts the HTTPS traffic, converting it to HTTP. The CSS then chooses a service and sends the HTTP traffic to a HTTP Web server. The following is a working CSS configuration &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the following URL for Requesting and Installing a Server Certificate on the CSS11500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_configuration_example09186a00801ffdcb.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_configuration_example09186a00801ffdcb.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sachin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2009 22:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155011#M23920</guid>
      <dc:creator>sachinga.hcl</dc:creator>
      <dc:date>2009-04-08T22:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: CSS: "ssl-server 10 rsacert" command was deleted during boot</title>
      <link>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155012#M23921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sachin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your information.&lt;/P&gt;&lt;P&gt;I'm studying your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2009 00:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-quot-ssl-server-10-rsacert-quot-command-was-deleted-during/m-p/1155012#M23921</guid>
      <dc:creator>snakayama</dc:creator>
      <dc:date>2009-04-09T00:02:56Z</dc:date>
    </item>
  </channel>
</rss>

