
Fabric OS 5.3.0 administrator guide 135
To set a secret key pair:
1.
Log in to the switch as admin
2.
On a switch running Fabric OS 4.x or 5.x, type
secAuthSecret --set
; on a switch running Fabric
OS v3.x, type
secAuthSecret "
--
set"
.
The command enters interactive mode. The command returns a description of itself and needed input;
then it loops through a sequence of switch specification, peer secret entry, and local secret entry. To exit
the loop, press
Enter
for the switch name; then type
y
.
switchA:admin>
secauthsecret --set
This command is used to set up secret keys for the DH-CHAP authentication.
The minimum length of a secret key is 8 characters and maximum 40
characters. Setting up secret keys does not initiate DH-CHAP
authentication. If switch is configured to do DH-CHAP, it is performed
whenever a port or a switch is enabled.
Warning: Please use a secure channel for setting secrets. Using
an insecure channel is not safe and may compromise secrets.
Following inputs should be specified for each entry.
1. WWN for which secret is being set up.
2. Peer secret: The secret of the peer that authenticates to peer.
3. Local secret: The local secret that authenticates peer.
Press Enter to start setting up shared secrets >
<cr>
Enter WWN, Domain, or switch name (Leave blank when done):
10:20:30:40:50:60:70:80
Enter peer secret:
<hidden>
Re-enter peer secret:
<hidden>
Enter local secret:
<hidden>
Re-enter local secret:
<hidden>
Enter WWN, Domain, or switch name (Leave blank when done):
10:20:30:40:50:60:70:81
Enter peer secret:
<hidden>
Re-enter peer secret:
<hidden>
Enter local secret:
<hidden>
Re-enter local secret:
<hidden>
Enter WWN, Domain, or switch name (Leave blank when done):
<cr>
Are you done? (yes, y, no, n): [no]
y
Saving data to key store… Done.
3.
Enable and disable the ports on a peer switch using the
portEnable
and
portDisable
commands.
Fabric wide distribution of the Auth policy
The AUTH policy can be manually distributed to the fabric using the
distribute
command; there is no
support for automatic distribution. Since this policy is distributed manually, you cannot set fabric-wide
consistency policy (fddcfg –-fabwideset) for automatic fabric-wide distribution.
To distribute the AUTH policy, see
“To distribute the local ACL policies:”
on page -144 for instructions.
Accept distributions configuration parameter
Local Switch configuration parameters are needed to control whether a switch accepts or rejects
distributions of the AUTH policy using the distribute command and whether the switch may initiate
distribution of the policy. To set the local switch configuration parameter, refer to
Configuring the database
distribution settings
, page 143.
Summary of Contents for AA979A - StorageWorks SAN Switch 2/8V
Page 1: ...HP StorageWorks Fabric OS 5 3 x administrator guide Part number 5697 0244 November 2009 ...
Page 16: ...16 ...
Page 20: ...18 ...
Page 24: ...24 Introducing Fabric OS CLI procedures ...
Page 116: ...118 Maintaining configurations ...
Page 170: ...172 Managing administrative domains ...
Page 200: ...202 Installing and maintaining firmware ...
Page 222: ...224 Routing traffic ...
Page 274: ...286 Administering FICON fabrics ...
Page 294: ...306 Working with diagnostic features ...
Page 350: ...362 Administering Extended Fabrics ...
Page 438: ...440 Configuring the PID format ...
Page 444: ...446 Configuring McData Open Fabric mode ...
Page 450: ...452 Understanding legacy password behaviour ...