04-20-2011 08:19 AM
We recently updated one of our servers to a new SSL certificate using the 4096 bit cipher key. Now the ACE probe to that server fails.
We have SSL version set to any and SSL cipher set to any. Id there a problem with a ACE https probe not supporting cipher keyes longer then 1024 bit ?
04-20-2011 09:20 AM
Hello DLance,
The ACE supports ssl certs upto 2048bits..
If you refer to the following guide, there is mention of the 2048 limit:
HTH. Regards.
04-20-2011 09:21 AM
More clarification on my last post - this is for both SSL offload and the ACE probing an SSL based rserver(s) - 2048 is the upper limit. Regards.
04-20-2011 09:29 AM
Thanks
I wonder if Cisco has any plans to change that ?
Dave
04-20-2011 09:33 AM
This link is blocked for me
Dave
04-20-2011 09:36 AM
Also we are running
ACE 4710 Device Manager A3(2.6)
Do you know if it will support 2048 bit keys ?
Dave
04-20-2011 09:37 AM
Did you login to CCO first - If you go to ACE configuration guides you will be able to access the document.
Currently there are no plans to support a 4096bit Cert.
04-20-2011 09:38 AM
Yes I was logged in.
Not we arent even running version 4
Does the version we run support 2048 ?
Dave
04-20-2011 09:46 AM
Yes, you will be good. 2048 is supported in all A(2.x), A(4.x) and even the earlier versions..
Thanks.
04-20-2011 09:48 AM
Thanks much. I was able to browse to the document.
Dave
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide