Explains secure HTTPS access and provides guidance for configuring custom certificates, SSL ciphers and protocols, and Diffie-Hellman key exchange on Cisco APIC.
This chapter contains the following sections:
Custom certificates for HTTPS access
Use a custom certificate to secure HTTPS management access to the Cisco Application Centric Infrastructure (ACI) fabric.
Guidelines and limitations for custom certificates
Review the requirements and limitations for managing custom Secure Sockets Layer (SSL) certificates and certificate-based authentication.
SSL cipher configuration
Enable, disable, or remove Secure Sockets Layer (SSL) ciphers while retaining a valid cipher configuration for NGINX.
Configure a custom certificate for Cisco ACI HTTPS access by using the GUI
Configure a custom certificate to secure HTTPS access to the Cisco APIC cluster and fabric switches. Perform this procedure during a maintenance window because the NGINX web servers restart.
Configure default SSL protocols and Diffie-Hellman key exchange by using the GUI
Select the Transport Layer Security (TLS) versions and Diffie-Hellman key exchange parameters that meet your security and application requirements.
Enable certificate-based authentication by using the NX-OS-style CLI
Configure certificate-based authentication for HTTPS access by specifying a certificate authority (CA) and enabling client certificate authentication.
SSL ciphers and TLS protocol support
Clients that access the Cisco Application Centric Infrastructure (ACI) REST API over HTTPS must support an enabled protocol version and cipher.