The show ssl config command displays the configuration details for SSL on the Sensor.
This command has no parameters.
Information displayed by the show ssl config command includes the following:
Whether SSL will be enabled the next time the Sensor reboots, and how many SSL flows will be supported
Whether SSL decryption is currently active and how many SSL flows are supported
How long the session is kept alive after the connection associated with that session ends (default is 5 minutes)
Whether the packet logging is enabled for attacks detected in an SSL tunnel
Whether SSL decryption keys are present on the Sensor
The number of SSL decryption keys present
Syntax:
show ssl config
Sample Output:
intruShell@john> show ssl config
[SSL Decryption Support]
Requested : no
Supported : Inbound (200000 flows)
[Inbound]
SSL Session Lifetime : 5 min
SSL Pkt Logging : disabled
SSL Shared Key Decrypt : enabled
[SSL Decryption Keys]
Present : no
Applicable to:
NS-series Sensors