9-19
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 9 Configuring SSL
Configuring SSL Parameter Maps
Step 4 Do the following:
• Click OK to export the key pair and to return to the Keys table.
• Click Cancel to exit this procedure without exporting the key pair and to return to the Keys table.
Related Topics
• Configuring SSL, page 9-1
• Importing SSL Certificates, page 9-8
• Importing SSL Key Pairs, page 9-12
• Generating SSL Key Pairs, page 9-15
• Configuring SSL Chain Group Parameters, page 9-25
• Configuring SSL CSR Parameters, page 9-26
• Configuring SSL Proxy Service, page 9-28
Configuring SSL Parameter Maps
An SSL parameter map defines the SSL session parameters that an ACE appliance applies to an SSL
proxy service. SSL parameter maps let you apply the same SSL session parameters to different proxy
services.
Use this procedure to create SSL parameter maps.
Procedure
Step 1 Choose Config > Virtual Contexts > context > SSL > Parameter Maps. The Parameter Maps table
appears.
Step 2 Click Add to add a new SSL parameter map, or select an existing entry to modify, and then click Edit.
The Parameter Map configuration screen appears.
Step 3 In the Parameter Map Name field, enter a unique name for the parameter map. Valid entries are
alphanumeric strings with a maximum of 64 characters.
Step 4 In the Description field, enter a brief description of the parameter map. Enter a text string with a
maximum of 240 alphanumeric characters (A–Z, a–z, 0–9). Spaces and special characters are allowed.
Enter double quotes as matching pairs.
Step 5 In the Queue Delay Timeout (Milliseconds) field, set the amount of time (in milliseconds) to wait before
emptying the queued data for encryption. The default delay is 200 milliseconds, and can be adjusted
from 0 (disabled) to 10000. If disabled (set to 0), the ACE encrypts the data from the server as soon as
it arrives and then sends the encrypted data to the client.
Note The Queue Delay Timeout is only applied to data that the SSL module sends to the client. This
avoids a potentially long delay in passing a small HTTP GET to the real server.
Step 6 In the Session Cache Timeout (Milliseconds) field, specify a timeout value of an SSL session ID to
remain valid before the ACE requires the full SSL handshake to establish a new SSL session. This value
allows the ACE to reuse the master key on subsequent connections with the client, which can speed up
Comments to this Manuals