Generated Certificate Key Size
Click the drop-down menu button and select the size of the RSA key that the VPN Concentrator uses in
its self-signed (generated) SSL server certificate. A larger key size increases security, but it also
increases the processing necessary in all transactions over SSL. The increases vary depending on the
type of transaction (encryption or decryption).
Choices are:
Apply / Cancel
To apply your SSL settings, and to include your settings in the active configuration, click Apply . The
Manager returns to the Configuration | System | Management Protocols screen.
Reminder:
To save the active configuration and make it the boot configuration, click the Save Needed icon at the
top of the Manager window.
To discard your settings, click Cancel . The Manager returns to the Configuration | System | Management
Protocols
VPN 3000 Concentrator Series User Guide
= The server insists on TLS Version 1 but accepts an initial SSL Version 2
TLS V1 with SSL V2 Hello
"Hello." At present, only Microsoft Internet Explorer 5.0 supports this option.
512-bit RSA Key
= This key size provides sufficient security. It is the most common, and requires the
least processing.
768-bit RSA Key
= This key size provides normal security and is the default selection. It requires
approximately 2 to 4 times more processing than the 512-bit key.
1024-bit RSA Key
= This key size provides high security. It requires approximately 4 to 8 times more
processing than the 512-bit key.
screen.
Configuration | System | Management Protocols | SSL
End of Chapter
9-13