Configuring Secure Socket Layer (SSL)
Terminology
HP
Switch
(SSL
Server)
SSL Client
Browser
1. Switch-to-Client SSL Cert.
2. User-to-Switch (login password and
enable password authentication)
options:
– Local
–
– RADIUS
Figure 7-1. Switch/User Authentication
SSL on the HP ProCurve switches supports these data encryption methods:
■
3DES (168-bit, 112 Effective)
■
DES (56-bit)
■
RC4 (40-bit, 128-bit)
N o t e :
HP ProCurve switches use RSA public key algorithms and Diffie-Hellman. All
references to a key mean keys generated using these algorithms unless
otherwise noted
Terminology
■
SSL Server:
An HP switch with SSL enabled.
■
Key Pair:
Public/private pair of RSA keys generated by switch, of
which public portion makes up part of server host certificate and
private portion is stored in switch flash (not user accessible).
■
Digital Certificate:
A certificate is an electronic “passport” that is
used to establish the credentials of the subject to which the certificate
was issued. Information contained within the certificate includes:
name of the subject, serial number, date of validity, subject's public
key, and the digital signature of the authority who issued the certifi
cate. Certificates on Procurve switches conform to the X.509v3 stan
dard, which defines the format of the certificate.
7-3
Содержание ProCurve 2800 Series
Страница 2: ......
Страница 24: ...Getting Started To Set Up and Install the Switch in Your Network This page is intentionally unused 1 12 ...
Страница 44: ...Configuring Username and Password Security Front Panel Security This page is intentionally unused 2 20 ...
Страница 132: ...RADIUS Authentication and Accounting Messages Related to RADIUS Operation This page is intentionally unused 5 32 ...
Страница 182: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 7 22 ...
Страница 268: ...Configuring and Monitoring Port Security Operating Notes for Port Security This page is intentionally unused 9 38 ...
Страница 299: ......