Server Security - IBM p5 590 System Handbook

Table of Contents

Advertisement

Whether the secure system manager server is configured.
Whether the private key for this system manager server is installed.
Whether this system is configured as a Certificate Authority.
Certificate Authority
Define one HMC as a Certificate Authority to generate keys and certificates for
your HMC servers and clients.
A Certificate Authority verifies the identities of the HMC servers to ensure secure
communications between clients and servers. To define a system as a Certificate
Authority, you must be logged in as the hscroot user at the machine being
defined as the internal Certificate Authority. This procedure defines a system as
an internal Certificate Authority for HMC security and creates a public key ring file
for the Certificate Authority that you can distribute to all of the clients that access
the HMC servers.
A wizard guides you through configuring the Certificate Authority. After you
define the internal Certificate Authority, you can use the CA to create the private
key files for the HMCs that you want to manage remotely. Each HMC server must
have its private key and a certificate of its public key signed by a Certificate
Authority that is trusted by the HMC clients. The private key and the server
certificate are stored in the server's private key file.There is an option to copy the
private key ring files to a diskette so you can install them on your servers.
Note: You cannot perform the server security function using a remote client.

8.6.1 Server security

This option allows you to install the private key ring file that you have copied to
diskette from the HMC server that is acting as the Certificate Authority.Once you
have copied the private key file there is another option to configure the HMC as a
secure server so that secure, remote clients can be used to remotely manage the
HMC.
There is a remote client available for download from the HMC itself. It is called
the Web-based System Management remote client and there is a Windows
OS-based version and a Linux OS-based version. To run in secure mode a
second file needs to be downloaded to the client. This is also available for
download from the HMC.
To download the Web-based System Management remote client to your
Windows OS-based or Linux OS-based PC, type in the following address from
your Web Browser:
IBM Eserver p5 590 and 595 System Handbook
232

Advertisement

Table of Contents
loading

This manual is also suitable for:

P5 595

Table of Contents