7-3
Configuring Secure Socket Layer (SSL)
Terminology
Figure 7-1. Switch/User Authentication
SSL on the ProCurve switches supports these data encryption methods:
■
3DES (168-bit, 112 Effective)
■
DES (56-bit)
■
RC4 (40-bit, 128-bit)
N o t e
ProCurve switches use RSA public key algorithms and Diffie-Hellman. All
references to a key mean keys generated using these algorithms unless
otherwise noted
Terminology
■
SSL Server:
A ProCurve switch with SSL enabled.
■
Key Pair:
Public/private pair of RSA keys generated by switch, of
which public portion makes up part of server host certificate and
private portion is stored in switch flash (not user accessible).
■
Digital Certificate:
A certificate is an electronic “passport” that is
used to establish the credentials of the subject to which the certificate
was issued. Information contained within the certificate includes:
name of the subject, serial number, date of validity, subject's public
key, and the digital signature of the authority who issued the certifi-
cate. Certificates on Procurve switches conform to the X.509v3 stan-
dard, which defines the format of the certificate.
ProCurve
Switch
(SSL
Server)
SSL Client
Browser
1. Switch-to-Client SSL Cert.
2. User-to-Switch (login password and
enable password authentication)
options:
– Local
–
– RADIUS
Содержание ProCurve 2510-24
Страница 1: ...Access Security Guide 2510 www procurve com ProCurve Switches Q 11 XX 2510 24 U 11 XX 2510 48 ...
Страница 2: ......
Страница 3: ...ProCurve Series 2510 Switches Access Security Guide July 2008 ...
Страница 26: ...1 10 Getting Started Need Only a Quick Start ...
Страница 104: ...4 30 TACACS Authentication Configuring TACACS on the Switch ...
Страница 144: ...5 40 RADIUS Authentication Authorization and Accounting Messages Related to RADIUS Operation ...
Страница 174: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 196: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Страница 294: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Страница 308: ...10 14 Using Authorized IP Managers Operating Notes ...
Страница 316: ...8 Index ...
Страница 317: ......