9-1
9
Configuring Secure Socket Layer (SSL)
Overview
The switches covered in this guide use Secure Socket Layer Version 3 (SSLv3)
and support for Transport Layer Security(TLSv1) to provide remote web
access to the switches via encrypted paths between the switch and manage-
ment station clients capable of SSL/TLS operation.
N o t e
HP Switches use SSL and TLS for all secure web transactions, and all refer-
ences to SSL mean using one of these algorithms unless otherwise noted
SSL provides all the web functions but, unlike standard web access, SSL
provides encrypted, authenticated transactions. The authentication type
includes server certificate authentication with user password authentication.
N o t e
SSL in the switches covered in this guide is based on the OpenSSL software
toolkit. For more information on OpenSSL, visit
www.openssl.com
.
Server Certificate authentication with User Password
Authentication .
This option is a subset of full certificate authentication of
the user and host. It occurs only if the switch has SSL enabled. As in figure 9-
1, the switch authenticates itself to SSL-enabled web browser. Users on SSL
browser then authenticate themselves to the switch (operator and/or manger
levels) by providing passwords stored locally on the switch or on a
or RADIUS server. However, the client does not use a certificate to authenti-
cate itself to the switch.
Feature
Default
Menu
CLI
WebAgent
Generating a Self Signed Certificate on the switch
No
n/a
Generating a Certificate Request on the switch
No
n/a
n/a
Enabling SSL
Disabled
n/a
page 9-13
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......