Diffie-Hellman parameters generation and achieving PFS with DHE
Generate DH parameters by using the CLI
create ssl dhparam <dhFile> [<bits>] [-gen (2 | 5)]
create ssl dhparam Key-DH-1 512 -gen 2
Generate DH parameters by using the GUI
Achieve perfect forward secrecy with DHE
dhKeyExpSizeLimit parameter. You can set this parameter for an SSL virtual server or an SSL profile and then bind the profile to a virtual server.
DHcount is 0) on NetScaler MPX appliances. Thee parameters are generated without a significant drop in performance, because the operation is optimized. Earlier, the minimum DH count allowed was 500. That is, you cannot regenerate the key for up to 500 transactions.
Optimize DH parameters generation by using the CLI
1. add ssl profile <name> [-sslProfileType ( BackEnd | FrontEnd )] [-dhCount <positive_integer>] [-dh ( ENABLED | DISABLED) -dhFile <string>] [-dhKeyExpSizeLimit ( ENABLED | DISABLED)]
2. set ssl vserver <vServerName> [-sslProfile <string>]3. set ssl vserver <vServerName> [-dh ( ENABLED | DISABLED) -dhFile <string>] [-dhCount <positive_integer>] [-dhKeyExpSizeLimit ( ENABLED | DISABLED )]
Optimize DH parameters generation by using the GUI
-
Navigate to Traffic Management > Load Balancing > Virtual Servers, and open a virtual server.
-
In the SSL Parameters section, select Enable DH Key Expire Size Limit.