Exinda Network Orchestrator
4 Settings
|
480
To configure an SSL Acceleration server
1.
In the
Add SSL Acceleration Server
area, type a name for the server or application you wish to enable for SSL Accel-
eration.
2.
Type the
IPv4 Address
of the server running the SSL enabled application.
3.
Type the
Port
number running the SSL enabled application on the server.
4.
If the server has multiple SSL certificates with a Server Name Indication (
SNI
) specified, type the SNI extension in the
field. The server (without an SNI) must be added before the server with the same IP and port number and an SNI can be
added.
5.
Select the
Certificate
to use for re-encryption of the SSL session. The certificates available here are those that are con-
figured in the Certificate and Key page.
6.
Select the
Client Auth Certificate
to authenticate sessions on the SSL server.
7.
Select the type of validation to apply to the server's certificate.
None
— SSL Acceleration accepts and processes the connection even if the server's SSL certificate is invalid
or expired.
Reject
— SSL Acceleration does not processes the connection under any circumstances. The connection is
still accelerated, but is not SSL accelerated.
Certificate
— SSL Acceleration accepts and processes the connection only if the server's certificate matches
the specific certificate named in the Client Auth Certificate field. Otherwise, the connection is not processed.
Any CA
— SSL Acceleration accepts and processes the connection if the server's certificate matches any CA
certificate that is loaded on to the Exinda appliance.
Any
— SSL Acceleration accepts and processes the connection if the server's certificate matches any cer-
tificate (CA or non-CA) that is loaded on to the Exinda appliance.
8.
If
Certificate
is selected as the
Validation
type, select the certificate to validate against.
9.
If
Any CA
or
Any
is selected as the
Validation
type, select the
Cert Revoked Check
type.
None
— No check is performed. The client auth certificate is used regardless of whether the certificate is
revoked or not.
OCSP-AIA
— The Online Certificate Status Protocol (OCSP) Authority Information Access (AIA) check is per-
formed. The method uses the location of the authority embedded in the certificate to check for the certificate's
revocation status. Note that if the AIA location is not specified in the certificate when this option is chosen, then
the certification revoke check will not happen.
OCSP-Server
— The Online Certificate Status Protocol (OCSP) check is performed. This method presents an
OCSP Server URI
field where you can type the location of the authority to check for the certificate's revocation
status.
10.
Click
Add SSL Server
.
The servers are displayed at the top of the page, where they can be edited or deleted.
To edit an SSL Accelerated server
1.
Locate the server in the
SSL Acceleration Servers
list, and click
Edit
.
2.
Modify the settings for the server, and click
Apply Changes
. The settings for the server are changed.
To delete an SSL Accelerated server
1.
Locate the server in the
SSL Acceleration Servers
list, and click
Delete
. Servers with SNI extensions must be deleted
Summary of Contents for EXNV-10063
Page 369: ...Exinda Network Orchestrator 4 Settings 369 ...
Page 411: ...Exinda Network Orchestrator 4 Settings 411 Screenshot 168 P2P OverflowVirtualCircuit ...
Page 420: ...Exinda Network Orchestrator 4 Settings 420 Screenshot 175 Students OverflowVirtualCircuit ...