Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

CSS 11500 SSL Configuration Change

Hi,

We have CSS 11500 CSS with SSL module,

Any change in SSL configuration need ssl service suspension which bring down complete SSL enviroment.

Is their any way to change the SSL configuration without downtime?

Is their any ways to bring only one site which has change while other are still up?

I had configured

One SSL-proxy-list which contains 100 sites certificates.

i had bind ssl-proxy-list to ssl service which points to ssl module in slot 0.

Please let me know best configuration to reduce SSL downtimes.

Thanks in Advance

Aniruddha

1 ACCEPTED SOLUTION

Accepted Solutions

Re: CSS 11500 SSL Configuration Change

You only need to suspend the one you are working on.

3 REPLIES

Re: CSS 11500 SSL Configuration Change

Aniruddha --

Unless you break out multiple proxy-lists, you will have to suspend the ssl environment to make a change. Once your change is complete, you can reactivate it.

There are a few schools of thought.

First, you can create ssl proxy-lists for each similar groups of sites. Your 100 certificates would then be broken out into a few groups, and you would minimize impact on your suspend/activate actions.

Second, you could just try to make your changes very quickly and minimize the ssl impact by using one proxy-list.

Third, you can create a lot of proxy-lists (one per content group). This is a ton of management and ends up being a problem instead of a solution.

Hope that helps,

Tim

Rate if you find this sufficient

New Member

Re: CSS 11500 SSL Configuration Change

if i have multiple ssl-proxy list ,do i need to suspend service before change in any ssl-proxy list?

Re: CSS 11500 SSL Configuration Change

You only need to suspend the one you are working on.

137
Views
0
Helpful
3
Replies
CreatePlease to create content