Configuring Secure Socket Layer (SSL)
Configuring the Switch for SSL Operation
Table 8-1.Certificate Field Descriptions
Field Name
Description
Valid Start Date
This should be the date you desire to begin using the SSL
functionality.
Valid End Date
This can be any future date, however good security practices would
suggest a valid duration of about one year between updates of
passwords and keys.
Common name
This should be the IP address or domain name associated with the
switch. Your web browser may warn you if this field does not match
the URL entered into the web browser when accessing the switch
Organization
This is the name of the entity (e.g. company) where the switch is in
service.
Organizational
Unit
This is the name of the sub-entity (e.g. department) where the
switch is in service.
City or location
This is the name of the city where switch is in service
State name
This is the name of the state or province where switch is in service
Country code
This is the ISO two-letter country-code where switch is in service
For example, to generate a key and a new host certificate:
Generate New Key
Enter certificate Arguments
Generate New Certificate
Figure 8-3. Example of Generating a Self-Signed Server Host certificate on the CLI for the Switch.
N o t e s
“Zeroizing” the switch’s server host certificate or key automatically disables
SSL (sets
web-management ssl
to
No
). Thus, if you zeroize the server host
certificate or key and then generate a new key and server certificate, you must
also re-enable SSL with the web-management ssl command before the switch
can resume SSL operation.
8-11
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...