7-2
Configuring Secure Socket Layer (SSL)
Overview
Overview
The ProCurve switches covered by this manual use Secure Socket Layer
Version 3 (SSLv3) and support for Transport Layer Security(TLSv1) to provide
remote web access to the switches via encrypted paths between the switch
and management station clients capable of SSL/TLS operation.
N o t e
ProCurve switches use SSL and TLS for all secure web transactions, and all
references to SSL mean using one of these algorithms unless otherwise noted
SSL provides all the web functions but, unlike standard web access, SSL
provides encrypted, authenticated transactions. The authentication type
includes server certificate authentication with user password authentication.
N o t e
SSL in ProCurve switches is based on the OpenSSL software toolkit. For more
information on OpenSSL, visit
http://www.openssl.com
.
Server Certificate authentication with User Password
Authentication .
This option is a subset of full certificate authentication of
the user and host. It occurs only if the switch has SSL enabled. As in figure 7-
1, the switch authenticates itself to SSL enabled web browser. Users on SSL
browser then authenticate themselves to the switch (operator and/or manger
levels) by providing passwords stored locally on the switch or on a
or RADIUS server. However, the client does not use a certificate to authenti-
cate itself to the switch.
Feature
Default
Menu
CLI
Web
Generating a Self Signed Certificate on the switch
No
n/a
page 7-8
page 7-12
Generating a Certificate Request on the switch
No
n/a
n/a
page 7-15
Enabling SSL
Disabled
n/a
page 7-17
page 7-19
Содержание ProCurve 2510-24
Страница 1: ...Access Security Guide 2510 www procurve com ProCurve Switches Q 11 XX 2510 24 U 11 XX 2510 48 ...
Страница 2: ......
Страница 3: ...ProCurve Series 2510 Switches Access Security Guide July 2008 ...
Страница 26: ...1 10 Getting Started Need Only a Quick Start ...
Страница 104: ...4 30 TACACS Authentication Configuring TACACS on the Switch ...
Страница 144: ...5 40 RADIUS Authentication Authorization and Accounting Messages Related to RADIUS Operation ...
Страница 174: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 196: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Страница 294: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Страница 308: ...10 14 Using Authorized IP Managers Operating Notes ...
Страница 316: ...8 Index ...
Страница 317: ......