9-32
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 9 Configuring SSL
Enabling Client Authentication
• At least one SSL certificate is available.
Use the following procedures to enable or disable client authentication:
• Configuring SSL Proxy Service, page 9-28
• Configuring SSL Authentication Groups, page 9-32
• Configuring CRLs for Client Authentication, page 9-33
Configuring SSL Authentication Groups
On the ACE, you can implement a group of certificates that are trusted as certificate signers by creating
an authentication group. After creating the authentication group and assigning its certificates, then you
can assign the authentication group to a proxy service in an SSL termination configuration to enable
client authentication. For information on client authentication, see Enabling Client Authentication,
page 9-31.
For information on server authentication and assigning an authentication group, see Configuring SSL
Proxy Service, page 9-28.
Use this procedure to specify the certificate authentication groups that the ACE uses during the SSL
handshake and enable client authentication on this SSL-proxy service. The ACE includes the certificates
configured in the group along with the certificate that you specified for the SSL proxy service.
Assumptions
• At least one SSL certificate is available.
• Your ACE appliance supports authentication groups.
Procedure
Step 1 Choose Config > Virtual Contexts > context > SSL > Auth Group Parameters.
The Auth Group Parameters table appears.
Step 2 Click Add to add a authentication group, or select an existing auth group, and then click Edit to modify
it. The Auth Group Parameters configuration screen appears.
Step 3 In the Name field, enter a unique name for the auth group. Valid entries are alphanumeric strings with a
maximum of 64 characters.
Step 4 Do the following:
• Click Deploy Now to deploy this configuration on the ACE. The updated Auth Group Parameters
screen appears along with the Auth Group Certificates table. Continue with Step 5.
• Click Cancel to exit the procedure without saving your entries and to return to the Auth Group
Parameters table.
• Click Next to deploy your entries and to add another entry to the Auth Group Parameters table.
Step 5 In the Auth Group Certificate field, click Add to add an entry. The Auth Group Certificates
configuration screen appears.
Note You cannot modify an existing entry in the Auth Group Certificates table. Instead, delete the
entry, and then add a new one.
Step 6 In the Certificate Name field, select the certificate to add to this auth group.
Comments to this Manuals