9-9
Configuring Secure Socket Layer (SSL)
Configuring the Switch for SSL Operation
Table 9-1.
Certificate Field Descriptions
For example, to generate a new host certificate:
Figure 9-2. Example of Generating a Self-Signed Server Host certificate on the CLI for the Switch
N o t e
“Zeroizing” the switch’s server host certificate or key automatically disables
SSL (sets
web-management ssl
to
No
). Thus, if you zeroize the server host
certificate or key and then generate a new key and server certificate, you must
also re-enable SSL with the web-management ssl command before the switch
can resume SSL operation.
Field Name
Description
Valid Start Date
This should be the date you desire to begin using the SSL
functionality.
Valid End Date
This can be any future date, however good security practices would
suggest a valid duration of about one year between updates of
passwords and keys.
Common name
This should be the IP address or domain name associated with the
switch. Your web browser may warn you if this field does not match
the URL entered into the web browser when accessing the switch
Organization
This is the name of the entity (e.g. company) where the switch is in
service.
Organizational
Unit
This is the name of the sub-entity (e.g. department) where the
switch is in service.
City or location
This is the name of the city where switch is in service
State name
This is the name of the state or province where switch is in service
Country code
This is the ISO two-letter country-code where switch is in service
HP Switch(config)# crypto host-cert generate self-signed
Validity start date [05/17/2011]: 05/31/2011
Validity end date [05/31/2012]: 06/15/2011
Common name [10.115.134.111]: 10.255.255.255
Organizational unit [Dept Name]: Hewlett-Packard
Organization [Company Name]: HP Networking
City or location [City]: Roseville
State name [State]: CA
Country code [US]: US
Generate New Certificate
Enter certificate Arguments
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......