| | Add Decryption Profile / Update Decryption Profile |
| Add a Decryption Profile.Update a Decryption Profile. |
| Sample Configuration | |
|---|---|
| Parameter | Mandatory | Default | Description |
|---|---|---|---|
| Name | Yes | Specify a name for the Decryption Profile. Name confines to:
| |
| Description | No | Specify a description for the Decryption Profile. Description confines to:
| |
| IsDefault | No | no | Read-only field specifying if it's a default decryption profile. |
| UseDefaultCAs | No | yes | Enable to use CAs specified in TLS/SSL settings for re-signing. UseDefaultCAs confines to:
|
| RSACA | No | Select the RSA CA for re-signing. | |
| ECCA | No | Select the EC CA for re-signing. | |
| BlockInvalidDate | No | no | Enable to block certificates with an invalid date. BlockInvalidDate confines to:
|
| BlockUntrustedIssuer | No | no | Enable to block certificates with an untrusted issuer. BlockUntrustedIssuer confines to:
|
| BlockSelfSigned | No | no | Enable to block self-signed certificates. BlockSelfSigned confines to:
|
| BlockRevoked | No | no | Enable to block revoked certificates. BlockRevoked confines to:
|
| BlockNameMismatch | No | no | Enable to block certificates with mismatched names. BlockNameMismatch confines to:
|
| BlockOtherReasons | No | no | Enable to block certificates with other errors. BlockOtherReasons confines to:
|
| MinTLSVersion | No | TLS v1.0 | Select minimum allowed SSL/TLS version. |
| MaxTLSVersion | No | Maximum supported | Select maximum allowed SSL/TLS version. |
| BlockAction | No | Reject and notify | Specify the block action for the Decryption Profile. BlockAction confines to:
|
| UnrecognizedCiphers | No | Allow without decryption | Specify the action for unrecognized cipher suites. UnrecognizedCiphers confines to:
|
| SSLConnectionsExceeded | No | Use SSL/TLS settings default | Specify the action for exceeded SSL connections. SSLConnectionsExceeded confines to:
|
| SSLv2SSLv3 | No | Use SSL/TLS settings default | Specify the action to be used for SSL 2.0 and SSL 3.0. SSLv2SSLv3 confines to:
|
| SSLCompression | No | Use SSL/TLS settings default | Specify the action for connections using SSL compression. SSLCompression confines to:
|
| KeyExchangeAlgorithm | No | Specify blocked key exchange algorithms the profile contains. | |
| AuthenticationAlgorithm | No | Specify blocked authentication algorithms the profile contains. | |
| BlockAndStreamCipher | No | Specify blocked block and stream cipher algorithms the profile contains. | |
| HashAlgorithm | No | Specify blocked hash algorithms the profile contains. | |
| MinRSAKeySize | No | 1024 | Specify the minimum allowed RSA key size. MinRSAKeySize confines to:
|
| NewName | No | Edit the name for the Decryption Profile. |
| Operation | Status | Message |
|---|---|---|
| Add Decryption Profile | 200 | |
| Add Decryption Profile | 500 | |
| Add Decryption Profile | 502 | |
| Add Decryption Profile | 522 | |
| Update Decryption Profile | 200 | |
| Update Decryption Profile | 500 |