Note
When the array is in FIPS mode and a certificate is generated off-array, in addition to
the certificate being in PEM format, the private key needs to be in PKCS#1 format.
You can use an openssl command to do this conversion. Once the .cer and .pk files are
generated, this additional step is required when the certificate will be used on an array
in FIPS mode.
To increase security, some organizations use CA certificate chaining. Certificate
chaining links two or more CA certificates together. The primary CA certificate is the
root certificate at the end of the CA certificate chain. Since the system needs the
complete certificate chain to verify the authenticity of a certificate that is received,
ask the directory server administrator if certificate chaining is used. If so, you must
concatenate all the relevant certificates into a single file and upload that version. The
certificate must be in PEM/Base64 encoded format and use the suffix .cer.
Storage system interfaces, services, and features that
support Internet Protocol version 6
You can configure the interfaces on a system and use Internet Protocol version 6
(IPv6) addresses to configure different services and features. The following list
contains features where IPv6 protocol is supported:
l
Interfaces (SF, iSCSI) - to statically assign an IPv4 or IPv6 address to an interface
l
Hosts - to enter a network name, an IPv4 address or an IPv6 address of a host
l
Routes - to configure a route for IPv4 or IPv6 protocol
l
Diagnostics - to initiate a diagnostic
ping
CLI command using either an IPv4 or
IPv6 destination address. In Unisphere select Settings
>
Access
>
Routing
>
Ping/Trace to access the Ping/Trace screen which supports the IPv6 destination
addresses as well.
All storage system components support IPv4, and most support IPv6.
Table 12
on
page 42 shows the availability of IPv6 support by setting type and component:
Table 12 IPv6 support by setting type and component
Setting Type
Component
IPv6 Supported
Unisphere management
settings
Management port
Yes
Domain Name Server (DNS)
Yes
NTP (network time protocol)
server
Yes
Remote logging server
Yes
LDAP server
No
Unisphere host configuration
setting
Microsoft Exchange
Yes
VMware datastore (NFS)
Yes
VMware datastore (VMFS)
Yes
Hyper-V datastore
Yes
Communication Security
42
EMC Unity All Flash, EMC Unity Hybrid, EMC UnityVSA
4.0
Security Configuration Guide
Содержание EMC Unity All Flash
Страница 32: ...Logging 32 EMC Unity All Flash EMC Unity Hybrid EMC UnityVSA 4 0 Security Configuration Guide...
Страница 60: ...Security Maintenance 60 EMC Unity All Flash EMC Unity Hybrid EMC UnityVSA 4 0 Security Configuration Guide...
Страница 70: ...TLS cipher suites 70 EMC Unity All Flash EMC Unity Hybrid EMC UnityVSA 4 0 Security Configuration Guide...