The show ssl config command displays the configuration details for SSL on the Sensor.
This command has no parameters.
Information displayed by the show ssl config command includes the following:
- Whether SSL will be enabled the next time the Sensor reboots, and how many SSL flows will be supported
- Whether SSL decryption is currently active and how many SSL flows are supported
- How long the session is kept alive after the connection associated with that session ends (default is 5 minutes)
- Whether the packet logging is enabled for attacks detected in an SSL tunnel
- Whether SSL decryption keys are present on the Sensor
- The number of SSL decryption keys present
Syntax:
show ssl config
Sample Output:
intruShell@john> show ssl config
[SSL Decryption Support]
Requested : no
Supported : Inbound (200000 flows)
[Inbound]
SSL Session Lifetime : 5 min
SSL Pkt Logging : disabled
SSL Shared Key Decrypt : enabled
[SSL Decryption Keys]
Present : no
Applicable to:
NS-series Sensors