Target
Specifiable
options
Usable protocols
plaintext
encryption
If you update the firmware version of the management module to A0205 or later
while the LPAR manager is running, transmissions will continue to use plain text.
Transmissions will be encrypted beginning from the next time that the LPAR
manager is started.
Note:
•
To use HVM Navigator via a plain-text connection, set "Default" for the
HCSM and HvmSh instances of the functions and tools that use a
management network.
•
If "High" is set for the HCSM or HvmSh instances of the functions or tools
that use a management network, configure HVM Navigator so that it uses
TLS.
Changing security strength
You can set the security strength by using HvmSh. For details about the
command, see the HVM Management Command (HvmSh) operation Guide.
You can also use the Web console to make this setting. For details, see the
Hitachi Compute Blade 500 Series Web Console User's Guide.
It may take about 30 seconds before the new security value is enabled, while
connection to LPAR manager may be unavailable for that period.
Encryption algorithm supported by LPAR manager
The following table shows encryption algorithm supported by LPAR manager.
Table 3-48 SSL/TLS
Cipher suites
Security strength
Default
High
TLS_RSA_WITH_AES_128_CBC_SHA
Y
-
TLS_RSA_WITH_AES_128_CBC_SHA256
Y
Y
TLS_RSA_WITH_AES_256_CBC_SHA256
Y
Y
TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA
Y
-
TLS_RSA_WITH_3DES_EDE_CBC_SHA
Y
-
TLS_DHE_DSS_AES_128_CBC_SHA1
Y
1
-
TLS_DHE_DSS_AES_256_CBC_SHA1
Y
1
-
TLS_DHE_DSS_AES_128_CBC_SHA256
Y
1
-
TLS_DHE_DSS_AES_256_CBC_SHA256
Y
1
-
TLS_RSA_AES_256_CBC_SHA1
Y
1
-
High Reliability Functions
3-39
Hitachi Compute Blade 500 Series Logical partitioning manager User's Guide