LPAR manager certificates
When the other system tries to connect to LPAR manager over TLS, the LPAR
manager certificate is sent to the other system. The other system can
authenticate the LPAR manager by verifying the server certificate.
•
LPAR manager server certificates
LPAR manager can use self signed certificates or certificates signed by a
certificate authority (CA) as the LPAR manager server certificate. When
the other system authenticates LPAR manager by verifying the LPAR
manager server certificate, register the server certificate to the other
system. For registration, see the other system's user's guide. It may take
about 30 seconds before a registered certificate is enabled, while
connection to LPAR manager may be unavailable for that period.
•
Systems for LPAR manager server certificates
The following systems can use LPAR manager server certificates.
– HCSM (Hitachi Compute Systems Manager)
– HvmSh
•
Server certificate parameters The following table describes parameters of
LPAR manager server certificates.
Table 3-39 Parameters of LPAR manager server certificates
Item
Description
Public key algorithm, bit- length
RSA (2048 bits)
Signature algorithm
SHA-2, etc.
7
Importable certificate format
PEM/DER
Certificate format in downloading
DER
Executable CSR format
PEM/DER
Subject information usable in a certificate
and CSR
Common name (CN): Up to 60
characters
1, 2
Country (C): Up to 2 characters
3
State or province (ST): Up to 60
characters
4
Locality (L): Up to 60 characters
4
Organization name: Up to 60 characters
4
Organization unit (OU): Up to 60
characters
4
Mail address: Up to 60 characters
5
DN qualifier: Up to 60 characters
4
Surname: Up to 60 characters
4
Given name: Up to 60 characters
4
High Reliability Functions
3-33
Hitachi Compute Blade 500 Series Logical partitioning manager User's Guide