<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cisco ACE SSL termination in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination/m-p/1570475#M32136</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;Naren,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. In order to import certs and keys, please see the following link to the command reference.&amp;nbsp; To summarize, any time you import/export/delete keys/certs, you are doing so via commands in exec mode.&amp;nbsp; Regarding how and where the ACE actually saves this information, I do not know this answer.&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/command/reference/execmds.html#wp1616651"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/command/reference/execmds.html#wp1616651&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You can import a key as non-exportable if you do not want it to be able to be exported. If you import it as exportable, you can always export it later for backups or what not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. You can decrypt captured HTTPS traffic if you have the private key.&amp;nbsp; It is important to limit access to it.&amp;nbsp; Please see this link for more info on using Wireshark to view decrypted HTTPS traffic: &lt;A class="active_link" href="http://wiki.wireshark.org/SSL"&gt;http://wiki.wireshark.org/SSL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Dec 2010 22:08:19 GMT</pubDate>
    <dc:creator>mgalazka</dc:creator>
    <dc:date>2010-12-14T22:08:19Z</dc:date>
    <item>
      <title>cisco ACE SSL termination</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination/m-p/1570474#M32135</link>
      <description>&lt;P&gt;Hello Friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need ur help on cisco ACE SSL termination.&lt;/P&gt;&lt;P&gt;If i import the certificate and key (.PEM), where this files will be saved ?&lt;/P&gt;&lt;P&gt;can we able to download the .PEM file any time as we need(back-up)?&lt;/P&gt;&lt;P&gt;suppose if my .PEM is got hacked, hacker is sniffing the data packet which going through the web server, can it be possiable to deencrypt the packet and see the exact packet ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Naren&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2010 20:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination/m-p/1570474#M32135</guid>
      <dc:creator>Naren naren</dc:creator>
      <dc:date>2010-12-14T20:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: cisco ACE SSL termination</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination/m-p/1570475#M32136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;Naren,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. In order to import certs and keys, please see the following link to the command reference.&amp;nbsp; To summarize, any time you import/export/delete keys/certs, you are doing so via commands in exec mode.&amp;nbsp; Regarding how and where the ACE actually saves this information, I do not know this answer.&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/command/reference/execmds.html#wp1616651"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/command/reference/execmds.html#wp1616651&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You can import a key as non-exportable if you do not want it to be able to be exported. If you import it as exportable, you can always export it later for backups or what not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. You can decrypt captured HTTPS traffic if you have the private key.&amp;nbsp; It is important to limit access to it.&amp;nbsp; Please see this link for more info on using Wireshark to view decrypted HTTPS traffic: &lt;A class="active_link" href="http://wiki.wireshark.org/SSL"&gt;http://wiki.wireshark.org/SSL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 22:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination/m-p/1570475#M32136</guid>
      <dc:creator>mgalazka</dc:creator>
      <dc:date>2010-12-14T22:08:19Z</dc:date>
    </item>
  </channel>
</rss>

