Change of HFA TLS Parameters
- CA/private certificate addition/removal
- Expiration of CA/private certificate (affects rekeying)
- CRL download
Static features:
- TLS version configuration
- TLS encryption configuration
- TLS key agreement configuration
- TLS AES operation mode configuration
Static features require SG reboot for the changes to take effect, which
is also indicated by icon in WBM. All dynamic features can be adjusted
during SG runtime. Such event triggers new SSL/TLS handshake and client
certificate chain verification with all consequences for all active connections.
All established calls should survive if handshake succeeds.