Fips Compliance; Enabling Configuration Encryption; Saving The Running Configuration - HP 5920 series Fundamentals Configuration Manual

Hide thumbs Also See for 5920 series:
Table of Contents

Advertisement

ip address 1.1.1.1 255.255.255.0
#

FIPS compliance

The device supports the FIPS mode that complies with NIST FIPS 140-2 requirements. Support for features,
commands, and parameters might differ in FIPS mode and non-FIPS mode. For more information about
FIPS mode, see Security Configuration Guide.

Enabling configuration encryption

Configuration encryption enables the device to encrypt a startup configuration file automatically when it
saves the running configuration. All HP devices running Comware V7 software use the same private key
or public key to encrypt configuration files.
NOTE:
Only HP devices running Comware V7 software can decrypt the encrypted configuration files.
To enable configuration encryption:
Step
1.
Enter system view.
2.
Enable configuration
encryption.

Saving the running configuration

When saving the running configuration to a configuration file, you can specify the file as the next-startup
configuration file.
If you are specifying the file as the next-startup configuration file, use one of the following methods to
save the configuration:
Fast mode—Use the save command without the safely keyword. In this mode, the device directly
overwrites the target next-startup configuration file. If a reboot or power failure occurs during this
process, the next-startup configuration file is lost. You must specify a new startup configuration file
after the device reboots (see
Safe mode—Use the save command with the safely keyword. Safe mode is slower than fast mode,
but more secure. In safe mode, the system saves configuration in a temporary file and starts
overwriting the target next-startup configuration file after the save operation is complete. If a reboot
or power failure occurs during the save operation, the next-startup configuration file is still retained.
Use the safe mode if the power source is not reliable or you are remotely configuring the device.
To save the running configuration, use either of the following command in any view:
Command
system-view
configuration encrypt { private-key |
public-key }
"Specifying a next-startup configuration
94
Remarks
N/A
By default, configuration
encryption is disabled.
Configuration is saved
unencrypted.
file").

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents