<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, It depends what you mean in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/managing-certificates-and-keys-in-end-to-end-ssl/m-p/2716071#M42844</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It depends what you mean by end-to-end SSL. If you mean just passing the SSL traffic through without any additional processing then you don't need the cert/key on the ACE. However the phrase end-to-end, particularly in the ACE manuals means terminate the inbound SSL on the ACE and then re-initiate the SSL to the serverfarm - that is, a combination of SSL termination and SSL initiation. So you will need the cert and the key.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to create an ssl-proxy service object referencing the cert, key and chaingroup to terminate the SSL and another ssl-proxy service object for the ssl client side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2015 08:01:42 GMT</pubDate>
    <dc:creator>ciscocsoc</dc:creator>
    <dc:date>2015-06-16T08:01:42Z</dc:date>
    <item>
      <title>Managing Certificates and Keys in End-to-End SSL</title>
      <link>https://community.cisco.com/t5/application-networking/managing-certificates-and-keys-in-end-to-end-ssl/m-p/2716070#M42843</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to configure a Cisco ACE 4710 in End-to-End SSL mode and need to know if the ACE for this scenario requires corresponding key pairs or whether it is sufficient with the .crt certificate import.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this manual says that the&amp;nbsp;corresponding key pairs is only needed for the following applications:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;SSL termination&lt;/P&gt;&lt;P&gt;-&amp;nbsp;SSL initiation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/interfaces_modules/services_modules/ace/v3-00_A2/configuration/ssl/guide/sslgd/certkeys.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2015 16:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/managing-certificates-and-keys-in-end-to-end-ssl/m-p/2716070#M42843</guid>
      <dc:creator>albertofdez</dc:creator>
      <dc:date>2015-06-15T16:35:54Z</dc:date>
    </item>
    <item>
      <title>Hi, It depends what you mean</title>
      <link>https://community.cisco.com/t5/application-networking/managing-certificates-and-keys-in-end-to-end-ssl/m-p/2716071#M42844</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It depends what you mean by end-to-end SSL. If you mean just passing the SSL traffic through without any additional processing then you don't need the cert/key on the ACE. However the phrase end-to-end, particularly in the ACE manuals means terminate the inbound SSL on the ACE and then re-initiate the SSL to the serverfarm - that is, a combination of SSL termination and SSL initiation. So you will need the cert and the key.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to create an ssl-proxy service object referencing the cert, key and chaingroup to terminate the SSL and another ssl-proxy service object for the ssl client side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2015 08:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/managing-certificates-and-keys-in-end-to-end-ssl/m-p/2716071#M42844</guid>
      <dc:creator>ciscocsoc</dc:creator>
      <dc:date>2015-06-16T08:01:42Z</dc:date>
    </item>
    <item>
      <title>Hi Cathy, Thanks for the</title>
      <link>https://community.cisco.com/t5/application-networking/managing-certificates-and-keys-in-end-to-end-ssl/m-p/2716072#M42845</link>
      <description>&lt;P&gt;Hi Cathy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick response was what I imagined. Because I need the cert / key because I have to deal with requests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2015 08:22:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/managing-certificates-and-keys-in-end-to-end-ssl/m-p/2716072#M42845</guid>
      <dc:creator>albertofdez</dc:creator>
      <dc:date>2015-06-16T08:22:18Z</dc:date>
    </item>
  </channel>
</rss>

