1、首先创建一个PKI域:
[H3C] pki domain test
[H3C-pki-domain-test] undo crl check enable
(V5命令:crl check disable)
2、导入CA证书和local证书到PKI域中:
说明:V7防火墙可以使用设备自带证书,获取证书的方法请见文档《NGFW防火墙生成设备自带证书对的方法》(证书要传到根目录)
[H3C] pki import domain test der ca filename ca.cer
[H3C] pki import domain test p12 local filename https-server.p12
3、在配置视图下通过命令ssl server-policy policy-name进入服务器端策略视图,修改SSL加密套件,使其不再包含RC4算法:
system-view
[H3C]ssl server-policy test
[H3C-ssl-server-policy-test]ciphersuite ecdhe_rsa_aes_256_gcm_sha384 ecdhe_rsa_aes_256_cbc_sha384 rsa_aes_256_cbc_sha rsa_aes_256_cbc_sha256 rsa_aes_256_gcm_sha384
[F1000-AI-65-XM]dis ssl server-policy test
Total number of SSL server policies: 1
SSL server policy: test
Version-info:
SSL3.0: Disabled
TLS1.0: Disabled
TLS1.1: Disabled
TLS1.2: Enabled
GM-TLS1.1: Disabled
PKI domains: domaim, test
Ciphersuites:
ECDHE_RSA_AES_256_GCM_SHA384
ECDHE_RSA_AES_256_CBC_SHA384
RSA_AES_256_CBC_SHA
RSA_AES_256_CBC_SHA256
RSA_AES_256_GCM_SHA384
Session cache size: 500
Caching timeout: 3600 seconds
Client-verify: Disabled
Ciphersuite server-preferred: Disabled
4、引用PKI域:
[H3C-ssl-server-policy-test] pki-domain test
5、禁用当前对外提供的SSL服务,如HTTPS:
[H3C] undo ip https enable
[H3C] undo ip http enable
6、配置SSL服务如HTTPS服务引用前面自定义的SSL Server端策略:
[H3C] ip https ssl-server-policy test
7、重新使能SSL服务,例如重新使能HTTPS服务:
[H3C] ip https enable
[H3C] ip http enable