<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Initiation Server Certificate CRL check in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ssl-initiation-server-certificate-crl-check/m-p/378331#M6574</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope you mean that to do full authentication by checking CRL and Certificate ACLs. ssl module can do certificate caching to improve performance. Cat6k ssl module can do both client certificate authentication and server certificate authentication in ssl initiation case.Check with the below links for more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRL&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252254" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252254&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Certificate ACL&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252138" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252138&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Certificate caching&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252599" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252599&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Server Certificate authentication&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1280161" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1280161&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Feb 2005 15:27:31 GMT</pubDate>
    <dc:creator>thomas.chen</dc:creator>
    <dc:date>2005-02-11T15:27:31Z</dc:date>
    <item>
      <title>SSL Initiation Server Certificate CRL check</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-initiation-server-certificate-crl-check/m-p/378330#M6573</link>
      <description>&lt;P&gt;I got the SSL initiation setup working with the backend-server setup. The cleint certificate is checked via the CRL because there is CDP information in the certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However we like to validate also the servercertificate. When we use a ssl-server configuration you can put in the ssl-server 10 crl xx command, this can not be done in a backend-server config. Anybody an Idea how the check the servercertificate against a CRL. &lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2005 08:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-initiation-server-certificate-crl-check/m-p/378330#M6573</guid>
      <dc:creator>eddiemeijer</dc:creator>
      <dc:date>2005-02-07T08:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Initiation Server Certificate CRL check</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-initiation-server-certificate-crl-check/m-p/378331#M6574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope you mean that to do full authentication by checking CRL and Certificate ACLs. ssl module can do certificate caching to improve performance. Cat6k ssl module can do both client certificate authentication and server certificate authentication in ssl initiation case.Check with the below links for more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CRL&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252254" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252254&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Certificate ACL&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252138" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252138&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Certificate caching&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252599" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1252599&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Server Certificate authentication&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1280161" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/ssl_2_1/ssl_cfg/config.htm#1280161&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Feb 2005 15:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-initiation-server-certificate-crl-check/m-p/378331#M6574</guid>
      <dc:creator>thomas.chen</dc:creator>
      <dc:date>2005-02-11T15:27:31Z</dc:date>
    </item>
  </channel>
</rss>

