Fabric OS 6.2 administrator guide 161
8.
Enter the following command to block access to root:
userconfig --change root -e no
By disabling the root account, RADIUS and LDAP users with root roles are also blocked in FIPS mode.
9.
Verify that your switch is FIPS ready:
fipscfg --verify fips
10.
Enter the command
fipsCfg
--
enable fips
.
11.
Reboot the switch.
Disabling FIPS mode
1.
Log in to the switch using an account assigned the admin or securityAdmin role.
2.
Enter the command
fipsCfg
--
disable fips
.
3.
Reboot the switch.
4.
Enable the root account by following the bootprom:
userconfig --change root -e yes
5.
Enable access to the bootprom:
fipscfg –-enable bootprom
6.
Optional: Use the
configure
command to set switch to use non-signed firmware.
By keeping the switch set to use signed firmware, all firmware downloaded to the switch will have to be
signed with a key. For more information, see Chapter 8, ”
Configuring advanced security features
” on
page 117.
7.
Disable selftests by typing the following command:
fipscfg
--
disable selftests
8.
Disable IPFilter policies that were created to enable FIPS.
9.
Optional: Configure RADIUS server authentication protocol.
10.
Reboot the switch.
Zeroizing for FIPS
1.
Log in to the switch using an account assigned the admin or securityAdmin role.
2.
Enter the command
fipsCfg
--
zeroize
.
3.
Reboot the switch.
Displaying FIPS configuration
1.
Log in to the switch using an account assigned the admin or securityAdmin role.
2.
Enter the command
fipsCfg
--
showall
.
Содержание A7533A - Brocade 4Gb SAN Switch Base
Страница 1: ...HP StorageWorks Fabric OS 6 2 administrator guide Part number 5697 0016 Edition May 2009 ...
Страница 24: ...24 ...
Страница 99: ...Fabric OS 6 2 administrator guide 99 ...
Страница 100: ...100 Managing user accounts ...
Страница 118: ...116 Configuring standard security features ...
Страница 164: ...162 Configuring advanced security features ...
Страница 234: ...232 Installing and maintaining firmware ...
Страница 268: ...266 Administering advanced zoning ...
Страница 284: ...282 Configuring Enterprise class platforms ...
Страница 292: ...290 Routing traffic ...
Страница 294: ...292 Interoperability for merged SANs ...
Страница 302: ...300 Configuring the Distributed Management Server ...
Страница 334: ...332 iSCSI gateway service ...
Страница 340: ...338 Administering NPIV ...
Страница 407: ...Fabric OS 6 2 administrator guide 405 ...
Страница 408: ...406 Using the FC FC routing service ...
Страница 438: ...434 Administering extended fabrics ...
Страница 460: ...456 Administering ISL trunking ...
Страница 498: ...494 Configuring and monitoring FCIP extension services 556200 Bps 30s avg 491394 Bps lifetime avg ...
Страница 516: ...512 FICON fabrics ...
Страница 526: ...522 Configuring and monitoring FICON Extension Services ...
Страница 540: ...536 Configuring the PID format ...
Страница 544: ...540 Understanding legacy password behavior ...
Страница 546: ...542 Mixed fabric configurations for non merge SANs ...
Страница 550: ...546 Migrating from an MP Router to a 400 MP Router ...
Страница 558: ...554 Inband Management ...
Страница 572: ...568 ...