Chapter 5
Configuring Back-End SSL
Activating and Suspending an SSL Proxy List
To reset the reset the buffer size to the default of 65536, enter:
(config-ssl-proxy-list[ssl_list1])# no backend-server 20 tcp
buffer-share tx
Activating and Suspending an SSL Proxy List
Before you can activate an SSL proxy list, ensure that you have created at least
one virtual or back-end SSL server in the list (see the
"Configuring Virtual SSL
Servers for an SSL Proxy List"
section or the
"Specifying the Nagle Algorithm
for SSL TCP Connections"
section earlier in this chapter).
The CSS checks the SSL proxy list to verify that all of the necessary components
are configured, including verification of the certificate and key pair against each
other. If the verification fails, the certificate name is not accepted and the CSS
logs the error message
and does not
Certificate and key pair do not match
activate the SSL proxy list. You must either remove the configured key pair or
configure an appropriate certificate.
Use the active command to activate the new or modified SSL proxy list. For
example, enter:
(config-ssl-proxy-list[ssl_list1])# active
After you activate an SSL proxy list, you can add it to a service. See the
"Configuring a Service for Back-End SSL"
section later in this chapter.
No modifications to an SSL proxy list are permitted on an active list. Suspend the
Note
list prior to making changes, and then reactivate the SSL proxy list once the
changes are complete. Once you have modified the SSL proxy list, suspend the
SSL service, reactivate the SSL proxy list, and then reactivate the SSL service.
To view the virtual or back-end SSL servers in a list, use the show ssl-proxy-list
(see
Chapter 7, Displaying SSL Configuration Information and
Statistics).
Use the suspend command to suspend an active SSL proxy list.
To suspend an active SSL proxy list, enter:
(config-ssl-proxy-list[ssl_list1])# suspend
Cisco Content Services Switch SSL Configuration Guide
5-17
OL-5655-01