Configuring Secure Socket Layer (SSL)
Overview
Overview
Feature
Default
Menu
CLI
Web
Generating a Self Signed Certificate on the switch
No
n/a
page 8-9
Generating a Certificate Request on the switch
No
n/a
n/a
Enabling SSL
Disabled
n/a
page 8-17
The switches covered in this guide use Secure Socket Layer Version 3 (SSLv3)
and support for Transport Layer Security(TLSv1) to provide remote web
access to the switches via encrypted paths between the switch and manage
ment station clients capable of SSL/TLS operation.
N o t e
ProCurve Switches use SSL and TLS for all secure web transactions, and all
references to SSL mean using one of these algorithms unless otherwise noted
SSL provides all the web functions but, unlike standard web access, SSL
provides encrypted, authenticated transactions. The authentication type
includes server certificate authentication with user password authentication.
N o t e
SSL in the switches covered in this guide is based on the OpenSSL software
toolkit. For more information on OpenSSL, visit
http://www.openssl.com
.
Server Certificate authentication with User Password
Authentication .
This option is a subset of full certificate authentication of
the user and host. It occurs only if the switch has SSL enabled. As in figure 8-
1, the switch authenticates itself to SSL enabled web browser. Users on SSL
browser then authenticate themselves to the switch (operator and/or manger
levels) by providing passwords stored locally on the switch or on a
or RADIUS server. However, the client does not use a certificate to authenti
cate itself to the switch.
8-2
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......