88
Configuring standard security features
Browser and Java support
Fabric OS supports the following Web browsers for SSL connections:
•
Internet Explorer (Microsoft Windows)
•
Mozilla (Solaris and Red Hat Linux)
In countries that allow the use of 128-bit encryption, you should use the latest version of your browser. For
example, Internet Explorer 6.0 and later supports 128-bit encryption by default. You can display the
encryption support (called “cipher strength”) using the Internet Explorer
Help:About
menu option. If you
are running an earlier version of Internet Explorer, you might be able to download an encryption patch
from the Microsoft Web site at
http://www.microsoft.com
.
You should upgrade to the Java 1.4.2_03 Plug-in on your management workstation. To find the Java
version that is currently running, open the Java console and look at the first line of the window.
For more details on levels of browser and Java support, refer to the
Web Tools Administrator’s Guide
.
Summary of SSL procedures
You configure for SSL by obtaining, installing, and activating digital certificates for SSL support.
Certificates are required on all switches that are to be accessed through SSL.
You also need to install a certificate to the Java Plug-in on the management workstation, and you might
need to add a certificate to your Web browser.
Configuring for SSL involves these major steps, which are shown in detail in the next sections:
1.
Choose a CA.
2.
On each switch:
a.
Generate a public/private key (
secCertUtil genkey
command).
b.
Generate a certificate signing request (CSR) (
secCertUtil gencsr
command) and store the
CSR on an FTP server (
secCertUtil export
command).
3.
Obtain the certificates from the CA.
You can request a certificate from a CA through a Web browser. After you request a certificate, the CA
either sends certificate files by email (public) or gives access to them on a remote host (private). Typically,
the CA provides the certificate files listed in
Table 21
.
4.
On each switch:
a.
Install the certificate.
b.
Activate the certificate.
5.
If necessary, install the root certificate to the browser on the management workstation.
6.
Add the root certificate to the Java Plug-in keystore on the management workstation.
Choosing a certificate authority
To ease maintenance and allow secure out-of-band communication between switches, consider using one
certificate authority (CA) to sign all management certificates for a fabric. If you use different CAs,
management services operate correctly, but the Web Tools Fabric Events button is unable to retrieve events
for the entire fabric.
Table 22
SSL Certificate Files
Certificate File
Description
name
.crt
The switch certificate.
name
Root.crt
The root certificate. Typically, this certificate is already installed in
the browser, but if not, you must install it.
name
CA.crt
The CA certificate. It is not necessary to install this, but you can if
you want the CA name to be displayed in the browser window.
Summary of Contents for AE370A - Brocade 4Gb SAN Switch 4/12
Page 18: ...18 ...
Page 82: ...82 Managing user accounts ...
Page 102: ...102 Configuring standard security features ...
Page 126: ...126 Maintaining configurations ...
Page 198: ...198 Routing traffic ...
Page 238: ...238 Using the FC FC routing service ...
Page 260: ...260 Administering FICON fabrics ...
Page 280: ...280 Working with diagnostic features ...
Page 332: ...332 Administering Extended Fabrics ...
Page 414: ...398 Configuring the PID format ...
Page 420: ...404 Configuring interoperability mode ...
Page 426: ...410 Understanding legacy password behaviour ...
Page 442: ...426 ...
Page 444: ......
Page 447: ......