Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Configure default SSL protocols and Diffie-Hellman key exchange by using the GUI

Want to summarize with AI?

Log in

Select the Transport Layer Security (TLS) versions and Diffie-Hellman key exchange parameters that meet your security and application requirements.


Configure the protocol and key exchange settings according to the security policies of your organization and the requirements of your applications.

Procedure

  1. On the menu bar, choose Fabric > Fabric Policies .

  2. In the Navigation pane, choose Policies > Pod > Management Access > default .

  3. In the Work pane, configure the HTTPS settings.

    1. Under SSL Protocols , select each TLS version that your network allows and clear each version that your network does not allow.
    2. In Release 6.0(1), from the DH Param drop-down list, choose the Diffie-Hellman (DH) key size in bits.

      Choosing a key size enables standard DH key exchange in addition to elliptic curve Diffie-Hellman (ECDH) key exchange. Standard DH uses the selected key size. Choosing None enables only ECDH key exchange. ECDH always uses 256 bits.

      Beginning with Release 6.0(2), the system determines the DH parameters dynamically during the handshake with the client. You do not manually select a key size.

    3. Click Submit .