Previous Topic: Certificates and Keys

Next Topic: How DXserver Uses Certificates

SSL Processing

CA Directory handles DAP, LDAP, DSP and DISP protocols over an SSL connection. Each DSA will process SSL connections internally.

SSL processing is a based on OpenSSL. The OpenSSL library has been modified to limit the cipher suites to those that comply with U.S. export controls and the terms of the CA Directory encryption export license, and to include HSM support. Symmetric keys are limited to 256 bits or less, and asymmetric keys, used in key exchange, are limited to 2048 bits.

CA Directory supports the following protocols: