Configuring Secure Socket Layer (SSL)
Terminology
ProCurve
Switch
(SSL
Server)
SSL Client
Browser
1. Switch-to-Client SSL Cert.
2. User-to-Switch (login password and
enable password authentication)
options:
– Local
–
– RADIUS
Figure 8-1. Switch/User Authentication
SSL on the switches covered in this guide supports these data encryption
methods:
■
3DES (168-bit, 112 Effective)
■
DES (56-bit)
■
RC4 (40-bit, 128-bit)
N o t e :
ProCurve Switches use RSA public key algorithms and Diffie-Hellman, and all
references to a key mean keys generated using these algorithms unless
otherwise noted
Terminology
■
SSL Server:
An ProCurve switch with SSL enabled.
■
Key Pair:
Public/private pair of RSA keys generated by switch, of which
public portion makes up part of server host certificate and private portion
is stored in switch flash (not user accessible).
■
Digital Certificate:
A certificate is an electronic “passport” that is used
to establish the credentials of the subject to which the certificate was
issued. Information contained within the certificate includes: name of the
subject, serial number, date of validity, subject's public key, and the digital
signature of the authority who issued the certificate. Certificates on
ProCurve switches conform to the X.509v3 standard, which defines the
format of the certificate.
■
Self-Signed Certificate:
A certificate not verified by a third-party cer
tificate authority (CA). Self-signed certificates provide a reduced level of
security compared to a CA-signed certificate.
■
CA-Signed Certificate:
A certificate verified by a third party certificate
authority (CA). Authenticity of CA-Signed certificates can be verified by
an audit trail leading to a trusted root certificate.
8-3
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......