Diffie-Hellman parameters generation and achieving PFS with DHE
Generate DH parameters by using the CLI
create ssl dhparam <dhFile> [<bits>] [-gen (2 | 5)]
create ssl dhparam Key-DH-1 512 -gen 2
Generate DH key of more than 2048 bits using the CLI
-
MPX 5900
-
MPX/SDX 8900
-
MPX/SDX 15000
-
MPX/SDX 15000-50G
-
MPX/SDX 26000
-
MPX/SDX 26000-50S
-
MPX/SDX 26000-100G
-
MPX/SDX 9100
-
MPX/SDX 16000
OpenSSL command from the NetScaler shell prompt.
Generate DH parameters by using the GUI
Achieve perfect forward secrecy with DHE
dhKeyExpSizeLimit parameter. You can set this parameter for an SSL virtual server or an SSL profile and then bind the profile to a virtual server.
DHcount is 0) on NetScaler MPX appliances. Thee parameters are generated without a significant drop in performance, because the operation is optimized. Earlier, the minimum DH count allowed was 500. That is, you cannot regenerate the key for up to 500 transactions.
Optimize DH parameters generation by using the CLI
1. add ssl profile <name> [-sslProfileType ( BackEnd | FrontEnd )] [-dhCount <positive_integer>] [-dh ( ENABLED | DISABLED) -dhFile <string>] [-dhKeyExpSizeLimit ( ENABLED | DISABLED)]
2. set ssl vserver <vServerName> [-sslProfile <string>]3. set ssl vserver <vServerName> [-dh ( ENABLED | DISABLED) -dhFile <string>] [-dhCount <positive_integer>] [-dhKeyExpSizeLimit ( ENABLED | DISABLED )]
Optimize DH parameters generation by using the GUI
-
Navigate to Traffic Management > Load Balancing > Virtual Servers, and open a virtual server.
-
In the SSL Parameters section, select Enable DH Key Expire Size Limit.