SSL profile infrastructure
ERROR: Specified parameters are not applicable for this type of SSL profile appears. Some SSL parameters, such as CRL memory size, OCSP cache size, UndefAction Control, and UndefAction Data, are not part of any profile, because these parameters are independent of entities. These parameters are present in Traffic Management > SSL > Advanced SSL Settings. For information about SSL parameters supported on a secure monitor, see Set SSL parameters on a secure monitor.
-
Add: Creates an SSL profile on the NetScaler appliance. Specify whether the profile is front end or back end. Default is front end.
-
Set: — Modifies the settings of an existing profile.
-
Unset: Sets the specified parameters to their default values. If you do not specify any parameters, an error message appears. If you unset a profile on an entity, the profile is unbound from the entity.
-
Remove: Deletes a profile. A profile that is being used by any entity cannot be deleted. Clearing the configuration deletes all the entities. As a result, the profiles are also deleted.
-
Bind: Binds a profile to an SSL entity.
-
Unbind: Unbinds a profile from an SSL entity.
-
Show: Displays all the profiles that are available on the NetScaler appliance. If a profile name is specified, the details of that profile are displayed. If an entity is specified, the profiles associated with that entity are displayed.
-
An SSL profile takes precedence over SSL parameters. That is, if you configure SSL parameters using the
set ssl parametercommand, and later bind a profile to an SSL entity, the settings in the profile take precedence. -
After the upgrade, if you enable the default profiles, you cannot undo the changes. That is, the profiles cannot be disabled. Save the configuration and create a copy of the configuration file (ns.conf) before enabling the profiles. However, if you do not want to use the features in the default profile, you can continue to use the old SSL profiles. For more information about these profiles, see Legacy SSL profile.
-
From release 11.1 51.x, in the GUI and CLI, a confirmation prompt is added when you enable the default profile to prevent enabling it by mistake.
ns_default_ssl_profile_internal_frontend_service profile is bound to the SSL internal services and SSLv3, TLSv1.0, and TLSv1.1 protocols are disabled in the profile.
set ssl parameter -defaultProfile ENABLED
Save your configuration before enabling the Default profile. You cannot undo the changes. Are you sure you want to enable the Default profile? [Y/N]Y
Done
Points to note
-
A profile can be bound to multiple virtual servers, but a virtual server can have only one profile bound to it.
-
To delete a profile that is bound to a virtual server, first unbind the profile.
-
A cipher or cipher group can be bound to multiple profiles at different priorities.
-
A profile can have multiple ciphers and cipher groups bound at different priorities.
-
Changes to a cipher group are immediately reflected in all the profiles and in all the virtual servers that one of the profiles is bound to.
-
If a cipher suite is part of a cipher group, edit the cipher group to remove that cipher suite before removing the cipher suite from the profile.
-
If you do not assign a priority to a cipher suite or cipher group attached to a profile, it is assigned the lowest priority within the profile.
-
You can create a custom cipher group (also called a user-defined cipher group) from existing cipher groups and cipher suites. If you create cipher group A and add existing cipher groups X and Y to it, in that order, Y is assigned at a lower priority than X. That is, the group that is added first has a higher priority.
-
If a cipher suite is part of two cipher groups attached to the same profile, the cipher suite is not added as part of the second cipher group. The cipher suite at the higher priority is in effect when traffic is processed.
-
Cipher groups are not expanded in the profile. As a result, the number of lines in the configuration file (ns.conf) is greatly reduced. For example, if two cipher groups containing 15 ciphers each are bound to a thousand SSL virtual servers, expansion adds 30*1000 cipher-related entries in the configuration file. With the new profile, it would have only two entries: one for each cipher group that is bound to a profile.
-
Creating a user-defined cipher group from existing ciphers and cipher groups is a copy-paste operation. Any changes in the original group are not reflected in the new group.
-
A user-defined cipher group lists all the profiles that it is a part of.
-
A profile lists all the SSL virtual server, services, and service groups that it is bound to.
-
If the default SSL profile feature is enabled, use the profile to set or change any of the attributes of an SSL entity. For example, virtual server, service, service group, or an internal service.
Save the configuration by using the CLI
save config
shell
root@ns# cd /nsconfig
root@ns# cp ns.conf ns.conf.NS<currentreleasenumber><currentbuildnumber>
save config
shell
root@ns# cd /nsconfig
root@ns# cp ns.conf ns.conf.NS.11.0.jun.16
Enable the default profile
-
Save your configuration before you upgrade the software and enable the default profiles.
-
From release 11.1 build 51.x, in the GUI and CLI, a confirmation prompt appears when you enable the default profile to avoid enabling it by mistake.
set ssl parameter -defaultProfile ENABLED
Save your configuration before enabling the Default profile. You cannot undo the changes. Are you sure you want to enable the Default profile? [Y/N]Y
Done
-
If a legacy profile (P1) is already bound to an SSL entity, and you enable the default profile, the default profile overrides the earlier binding. That is, the default profile is bound to the SSL entities. If you do not want the default profile to be bound, you must bind P1 to the SSL entity again.
-
A single operation (Enable Default Profile or
set ssl parameter -defaultProfile ENABLED) enables (binds) both the default front-end profile and the default back-end profile.
Parameters that are part of the default profiles
sh ssl profile ns_default_ssl_profile_frontend
sh ssl profile ns_default_ssl_profile_backend
> sh ssl profile ns_default_ssl_profile_frontend
1) Name: ns_default_ssl_profile_frontend (Front-End)
SSLv3: DISABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED TLSv1.3: DISABLED
Client Auth: DISABLED
Use only bound CA certificates: DISABLED
Strict CA checks: NO
Session Reuse: ENABLED Timeout: 120 seconds
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED Ephemeral RSA: ENABLED Refresh Count: 0
Deny SSL Renegotiation ALL
Non FIPS Ciphers: DISABLED
Cipher Redirect: DISABLED
SSL Redirect: DISABLED
Send Close-Notify: YES
Strict Sig-Digest Check: DISABLED
Zero RTT Early Data: DISABLED
DHE Key Exchange With PSK: NO
Tickets Per Authentication Context: 1
Push Encryption Trigger: Always
PUSH encryption trigger timeout: 1 ms
SNI: DISABLED
OCSP Stapling: DISABLED
Strict Host Header check for SNI enabled SSL sessions: NO
Match HTTP Host header with SNI: CERT
Push flag: 0x0 (Auto)
SSL quantum size: 8 kB
Encryption trigger timeout 100 mS
Encryption trigger packet count: 45
Subject/Issuer Name Insertion Format: Unicode
SSL Interception: DISABLED
SSL Interception OCSP Check: ENABLED
SSL Interception End to End Renegotiation: ENABLED
SSL Interception Maximum Reuse Sessions per Server: 10
Session Ticket: DISABLED
HSTS: DISABLED
HSTS IncludeSubDomains: NO
HSTS Max-Age: 0
HSTS Preload: NO
Allow Extended Master Secret: NO
Send ALPN Protocol: NONE
ECC Curve: P_256, P_384, P_224, P_521
1) Cipher Name: DEFAULT Priority :1
Description: Predefined Cipher Alias
> sh ssl profile ns_default_ssl_profile_backend
1) Name: ns_default_ssl_profile_backend (Back-End)
SSLv3: DISABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED TLSv1.3: DISABLED
Server Auth: DISABLED
Use only bound CA certificates: DISABLED
Strict CA checks: NO
Session Reuse: ENABLED Timeout: 300 seconds
DH: DISABLED
Ephemeral RSA: DISABLED
Deny SSL Renegotiation ALL
Non FIPS Ciphers: DISABLED
Cipher Redirect: DISABLED
SSL Redirect: DISABLED
Send Close-Notify: YES
Strict Sig-Digest Check: DISABLED
Push Encryption Trigger: Always
PUSH encryption trigger timeout: 1 ms
SNI: DISABLED
OCSP Stapling: DISABLED
Strict Host Header check for SNI enabled SSL sessions: NO
Push flag: 0x0 (Auto)
SSL quantum size: 8 kB
Encryption trigger timeout 100 mS
Encryption trigger packet count: 45
Allow Extended Master Secret: NO
ECC Curve: P_256, P_384, P_224, P_521
1) Cipher Name: DEFAULT_BACKEND Priority :1
Description: Predefined Cipher Alias
Done
Use case
-
For information about upgrading the software, see Upgrading the System Software.
-
Enable the default profiles by using the CLI or GUI.
-
At the command line, type:
set ssl parameter -defaultProfile ENABLED -
If you prefer to use the GUI, navigate to Traffic Management > SSL > Change advanced SSL settings, scroll down, and select Enable Default Profile.
-
-
(Optional) Manually change any settings in the default profile.
-
At the command line, type:
set ssl profile <name>followed by the parameters to modify. -
If you prefer to use the GUI, navigate to System > Profiles. In SSL Profiles, select a profile and click Edit.
-
SSL profile parameters
Support for secure renegotiation at the back end of a NetScaler appliance
-
VPX
-
MPX platforms containing N2 or N3 chips
-
Intel Coleto SSL chip based platforms
denySSLReneg parameter is set to ALL (default).
denySSLReneg parameter:
-
NO
-
FRONTEND_CLIENT
-
FRONTEND_CLIENTSERVER
-
NONSECURE
Enable secure renegotiation by using the CLI
set ssl profile <name> -denySSLReneg <denySSLReneg>
set ssl profile ns_default_ssl_profile_backend -denySSLReneg NONSECURE
Done
sh ssl profile ns_default_ssl_profile_backend
1) Name: ns_default_ssl_profile_backend (Back-End)
SSLv3: DISABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED TLSv1.3: DISABLED
Server Auth: DISABLED
Use only bound CA certificates: DISABLED
Strict CA checks: NO
Session Reuse: ENABLED Timeout: 300 seconds
DH: DISABLED
Ephemeral RSA: DISABLED
Deny SSL Renegotiation NONSECURE
Non FIPS Ciphers: DISABLED
Cipher Redirect: DISABLED
SSL Redirect: DISABLED
Send Close-Notify: YES
Strict Sig-Digest Check: DISABLED
Push Encryption Trigger: Always
PUSH encryption trigger timeout: 1 ms
SNI: DISABLED
OCSP Stapling: DISABLED
Strict Host Header check for SNI enabled SSL sessions: NO
Push flag: 0x0 (Auto)
SSL quantum size: 8 kB
Encryption trigger timeout 100 mS
Encryption trigger packet count: 45
ECC Curve: P_256, P_384, P_224, P_521
1) Cipher Name: DEFAULT_BACKEND Priority :2
Description: Predefined Cipher Alias
1) Service Name: s187
Done
Enable secure renegotiation by using the GUI
-
Navigate to System > Profiles > SSL Profile.
-
Add or edit a profile.
-
Set Deny SSL Renegotiation to any value other than ALL.Back-end secure renegotiation SSL profile
Host header validation
SNIHTTPHostMatch is added to an SSL profile and SSL global parameters to have better control on this validation. This parameter can take three values; CERT, STRICT, and NONE. These values work as follows for SNI enabled sessions only. SNI must be enabled on the SSL virtual server or the profile bound to the virtual server, and the HTTP request must contain the host header.
-
CERT - Connection is forwarded if the host header value in the request is covered by the certificate used to establish this SSL session.
-
STRICT - Connection is forwarded only if the host header value in the request matches the server name value passed in the Client Hello message of the SSL connection.
-
NO - The host header value is not validated.
SNIHTTPHostMatch there is a change in the behavior of the dropReqWithNoHostHeader parameter. The setting of the dropReqWithNoHostHeader parameter no longer affects how the host header is validated against the SNI certificate.
Set SSL profile parameters by using the CLI
set ssl profile <name> [-ssllogProfile <string>] [-dh ( ENABLED | DISABLED ) -dhFile <string>] [-dhCount <positive_integer>][-dhKeyExpSizeLimit ( ENABLED | DISABLED )] [-eRSA ( ENABLED | DISABLED) [-eRSACount <positive_integer>]] [-sessReuse ( ENABLED | DISABLED )
[-sessTimeout <positive_integer>]] [-cipherRedirect ( ENABLED | DISABLED ) [-cipherURL <URL>]] [-clientAuth ( ENABLED | DISABLED )[-clientCert ( Mandatory | Optional )]] [-sslRedirect ( ENABLED |
DISABLED )] [-redirectPortRewrite ( ENABLED | DISABLED )] [-ssl3 (ENABLED | DISABLED )] [-tls1 ( ENABLED | DISABLED )] [-tls11 ( ENABLED| DISABLED )] [-tls12 ( ENABLED | DISABLED )] [-tls13 ( ENABLED |DISABLED )] [-SNIEnable ( ENABLED | DISABLED )] [-ocspStapling (ENABLED | DISABLED )] [-serverAuth ( ENABLED | DISABLED )] [-commonName <string>] [-pushEncTrigger <pushEncTrigger>] [-sendCloseNotify ( YES |
NO )] [-clearTextPort <port|*>] [-insertionEncoding ( Unicode | UTF-8)] [-denySSLReneg <denySSLReneg>] [-quantumSize <quantumSize>]
[-strictCAChecks ( YES | NO )] [-encryptTriggerPktCount <positive_integer>] [-pushFlag <positive_integer>][-dropReqWithNoHostHeader ( YES | NO )] [-SNIHTTPHostMatch <SNIHTTPHostMatch>] [-pushEncTriggerTimeout <positive_integer>]
[-sslTriggerTimeout <positive_integer>] [-clientAuthUseBoundCAChain (ENABLED | DISABLED )] [-sslInterception ( ENABLED | DISABLED )][-ssliReneg ( ENABLED | DISABLED )] [-ssliOCSPCheck ( ENABLED | DISABLED )] [-ssliMaxSessPerServer <positive_integer>] [-HSTS ( ENABLED| DISABLED )] [-maxage <positive_integer>] [-IncludeSubdomains ( YES | NO )] [-preload ( YES | NO )] [-sessionTicket ( ENABLED | DISABLED )][-sessionTicketLifeTime <positive_integer>] [-sessionTicketKeyRefresh (ENABLED | DISABLED )] {-sessionTicketKeyData } [-sessionKeyLifeTime <positive_integer>] [-prevSessionKeyLifeTime <positive_integer>]
[-cipherName <string> -cipherPriority <positive_integer>][-strictSigDigestCheck ( ENABLED | DISABLED )]
[-skipClientCertPolicyCheck ( ENABLED | DISABLED )] [-zeroRttEarlyData ( ENABLED | DISABLED )] [-tls13SessionTicketsPerAuthContext
<positive_integer>] [-dheKeyExchangeWithPsk ( YES | NO )]
Set SSL profile parameters by using the GUI
-
Navigate to System > Profiles. System profiles
-
Select SSL Profiles. Click Add. SSL profile
-
Specify values for the different parameters. SSL profile parameters
-
Click OK.
-
Click Done.
-
Navigate to System > Profiles.
-
Select an existing profile and click Add.
-
Specify a different name, change any parameters, and click OK.
-
Click Done.
TLS session ticket extension
Limitations
-
This feature is not supported on a FIPS platform.
-
This feature is supported only with TLS versions 1.1 and 1.2.
-
SSL session ID persistency is not supported with session tickets.
Enable TLS session ticket extension by using the CLI
set ssl profile <name> -sessionTicket (ENABLED | DISABLED ) [-sessionTicketLifeTime <positive_integer>
add ssl profile profile1 -sessionTicket ENABLED -sessionTicketlifeTime 300
Done
Enable TLS session ticket extension by using the GUI
-
Navigate to System > Profiles. Select SSL Profiles.
-
Click Add and specify a name for the profile.
-
Select Session ticket.
-
Optionally, specify Session Ticket Lifetime (secs).
Secure implementation of session tickets
-
Session ticket name.
-
Session AES key used to encrypt or decrypt the ticket.
-
Session HMAC key used to compute the digest of the ticket.
sessionTicketKeyLifeTime parameter specifies how often a session-ticket key is refreshed. You can set the prevSessionTicketKeyLifeTime parameter to specify how long the previous session-ticket key will be maintained for decrypting tickets using that key, after a new key is generated. The prevSessionTicketKeyLifeTime setting extends the time for which a client can use an abbreviated handshake to reconnect. For example, if sessionTicketKeyLifeTime is set to 10 minutes and prevSessionTicketKeyLifeTime to 5 minutes, a new key is generated after 10 minutes and used for all new sessions. However, previously connected clients have another 5 minutes for which previously issued tickets are honored for an abbreviated handshake.
Configure SSL session-ticket data by using the CLI
set ssl profile <name> -sessionTicket ENABLED -sessionTicketLifeTime <positive_integer> -sessionTicketKeyRefresh ( ENABLED | DISABLED )] -sessionTicketKeyLifeTime <positive_integer> [-prevSessionTicketKeyLifeTime <positive_integer>]
set ssl profile ns_default_ssl_profile_frontend -sessionTicket ENABLED -sessionTicketlifeTime 120 -sessionTicketKeyRefresh ENABLED -sessionTicketKeyLifeTime 100 -prevSessionTicketKeyLifeTime 60
Done
show ssl profile ns_default_ssl_profile_frontend
Session Ticket: ENABLED
Session Ticket Lifetime: 120 (secs)
Session Key Auto Refresh: ENABLED
Session Key Lifetime: 100 (secs)
Previous Session Key Lifetime: 60 (secs)
Configure SSL session-ticket data by using the GUI
-
Navigate to System > Profiles, and select SSL Profile.
-
Select ns_default_ssl_profile_frontend and click Edit.
-
In the Basic Settings section, click the pencil icon and set the following parameters:
-
Session Ticket
-
Session Ticket Lifetime (secs)
-
Session Ticket Key Auto Refresh
-
Session Ticket Key Lifetime (secs)
-
Previous Session Ticket Key Lifetime (secs)
-
-
Click OK.
Type SSL session ticket data manually by using the CLI
set ssl profile <name> -sessionTicket ENABLED
set ssl profile <name> -sessionTicketKeyData
show ssl profile ns_default_ssl_profile_frontend
Contains the session ticket name (0–15 bytes), the session AES key used to encrypt or decrypt the session ticket (16–31 bytes), and the session HMAC key used to compute the digest of the ticket (32–63 bytes). Externally generated by an administrator and added to a NetScaler appliance.
set ssl profile ns_default_ssl_profile_frontend -sessionTicket ENABLED
Done
set ssl profile ns_default_ssl_profile_frontend -sessionTicketKeyData 111111111111111111111111111111111111111111111111
Done
show ssl profile ns_default_ssl_profile_frontend
1) Name: ns_default_ssl_profile_frontend (Front-End)
SSLv3: ENABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED
Client Auth: DISABLED
Use only bound CA certificates: DISABLED
Strict CA checks: NO
Session Reuse: ENABLED Timeout: 120 seconds
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED Ephemeral RSA: ENABLED Refresh Count: 0
Deny SSL Renegotiation ALL
Non FIPS Ciphers: DISABLED
Cipher Redirect: DISABLED
SSL Redirect: DISABLED
Send Close-Notify: YES
Push Encryption Trigger: Always
PUSH encryption trigger timeout: 1 ms
SNI: DISABLED
OCSP Stapling: DISABLED
Strict Host Header check for SNI enabled SSL sessions: NO
Push flag: 0x0 (Auto)
SSL quantum size: 8 kB
Encryption trigger timeout 100 mS
Encryption trigger packet count: 45
Subject/Issuer Name Insertion Format: Unicode
Session Ticket: ENABLED
Session Ticket Lifetime: 300 (secs)
Session Key Auto Refresh: DISABLED
Session Key Lifetime: 3000 (secs)
Previous Session Key Lifetime: 0 (secs)
Session Key Data: 84dad1afc6d56b0deeb0a7fd7f299a207e8d8c15cdd087a5684a11a329fd732e87a0535d90883
47e8c181ba266f5c8838ae472cb3ab9255b683bf922fad32cee816c329989ef7cdeb278e93ac37882e3
ECC Curve: P_256, P_384, P_224, P_521
1) Cipher Name: DEFAULT Priority :4
Description: Predefined Cipher Alias
1) Internal Service Name (Front-End): nsrnatsip-127.0.0.1-5061
2) Internal Service Name (Front-End): nskrpcs-127.0.0.1-3009
3) Internal Service Name (Front-End): nshttps-::1l-443
4) Internal Service Name (Front-End): nsrpcs-::1l-3008
5) Internal Service Name (Front-End): nshttps-127.0.0.1-443
6) Internal Service Name (Front-End): nsrpcs-127.0.0.1-3008
7) Vserver Name: v1
Done
Type SSL session ticket data manually by using the GUI
-
Navigate to System > Profiles, and select SSL Profile.
-
Select ns_default_ssl_profile_frontend and click Edit.
-
In the Basic Settings section, click the pencil icon and set the following parameters:
-
Session Ticket
-
Session Ticket Key Data
-
Confirm Session Ticket Key Data
-
-
Click OK.
Support for Extended Master Secret in SSL handshake on NetScaler non-FIPS platforms
Platform support for EMS
-
MPX and SDX platforms containing either Cavium N3 chips or Intel Coleto Creek crypto cards. The following platforms ship with Intel Coleto chips:
-
MPX 5900
-
MPX/SDX 8900
-
MPX/SDX 26000
-
MPX/SDX 26000-50S
-
MPS/SDX 26000-100G
-
MPX/SDX 15000-50G
show hardware command to identify whether your appliance has Coleto (COL) or N3 chips.
-
MPX and SDX platforms without crypto cards (software-only).
-
Software-only platforms: VPX, CPX, and BLX.
-
MPX 9700 FIPS and MPX 14000 FIPS platforms.
-
MPX and SDX platforms containing Cavium N2 crypto chips.
Enable EMS using the CLI
set ssl profile <profile name> [-allowExtendedMasterSecret (YES | NO)]
set ssl profile ns_default_ssl_profile_frontend -allowExtendedMasterSecret YES
set ssl profile ns_default_ssl_profile_backend -allowExtendedMasterSecret YES
allowExtendedMasterSecret parameter on different default and user-defined profiles.
| Profile | Default setting |
|---|---|
| Default front-end profile | NO |
| Default front-end secure profile | YES |
| Default back-end profile | NO |
| User-defined profile | NO |
Enable EMS using the GUI
-
Navigate to System > Profiles > SSL Profile.
-
Add a profile or edit a profile.
-
Set Allow Extended Master Secret to YES.EMS
Support for processing of ALPN extension in the client hello message
alpnProtocol is added to the front-end SSL profiles to negotiate the application protocol in the ALPN extension for the connections handled by the SSL_TCP virtual server. Only the protocol specified in the SSL profile is negotiated, if the same protocol is received in the ALPN extension of the client hello message.
alpnProtocol parameter is supported only on front end SSL profiles and is applicable to the SSL connections handled by SSL_TCP type virtual servers.
Set the protocol in the front-end SSL profile using the CLI
set ssl profile ns_default_ssl_profile_frontend -alpnProtocol <protocol_name>
alpnProtocol parameter can take three values. Maximum length: 4096 bytes.
-
NONE: Application protocol negotiation does not take place. This setting is the default.
-
HTTP1: HTTP1 can be negotiated as the application protocol.
-
HTTP2: HTTP2 can be negotiated as the application protocol.
set ssl profile ns_default_ssl_profile_frontend -ALPNProtocol HTTP2
> sh ssl profile ns_default_ssl_profile_frontend
1) Name: ns_default_ssl_profile_frontend (Front-End)
SSLv3: DISABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED TLSv1.3: DISABLED
Client Auth: DISABLED
Use only bound CA certificates: DISABLED
Strict CA checks: NO
Session Reuse: ENABLED Timeout: 120 seconds
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED Ephemeral RSA: ENABLED Refresh Count: 0
Deny SSL Renegotiation ALL
Non FIPS Ciphers: DISABLED
Cipher Redirect: DISABLED
SSL Redirect: DISABLED
Send Close-Notify: YES
Strict Sig-Digest Check: DISABLED
Zero RTT Early Data: DISABLED
DHE Key Exchange With PSK: NO
Tickets Per Authentication Context: 1
Push Encryption Trigger: Always
PUSH encryption trigger timeout: 1 ms
SNI: DISABLED
OCSP Stapling: DISABLED
Strict Host Header check for SNI enabled SSL sessions: NO
Match HTTP Host header with SNI: CERT
Push flag: 0x0 (Auto)
SSL quantum size: 8 kB
Encryption trigger timeout 100 mS
Encryption trigger packet count: 45
Subject/Issuer Name Insertion Format: Unicode
SSL Interception: DISABLED
SSL Interception OCSP Check: ENABLED
SSL Interception End to End Renegotiation: ENABLED
SSL Interception Maximum Reuse Sessions per Server: 10
Session Ticket: DISABLED
HSTS: DISABLED
HSTS IncludeSubDomains: NO
HSTS Max-Age: 0
HSTS Preload: NO
Allow Extended Master Secret: NO
Send ALPN Protocol: HTTP2
Done
Set the protocol in the front-end SSL profile using the GUI
-
Navigate to System > Profiles, and select SSL Profile.
-
Select ns_default_ssl_profile_frontend and click Edit.
-
In the ALPN Protocol list, select HTTP2.ALPN protocol selection in GUI
Load an old configuration
Load an old configuration by using the CLI
shell
root@ns# clear config
root@ns# cd /nsconfig
root@ns# cp ns.conf.NS.11.0.jun.16 ns.conf
root@ns# reboot