Fabric Wide Distribution Of The Auth Policy - HP A7533A - Brocade 4Gb SAN Switch Base Administrator's Manual

Hp storageworks fabric os 6.x administrator guide (5697-0015, may 2009)
Hide thumbs Also See for A7533A - Brocade 4Gb SAN Switch Base:
Table of Contents

Advertisement

To set a secret key pair:
Log in to the switch using an account assigned to the admin role.
1.
2.
On a switch running Fabric OS 4.x, 5.x, or 6.0, type secAuthSecret --set; on a switch running
Fabric OS 3.x, type secAuthSecret "
The command enters interactive mode. The command returns a description of itself and needed input; then
it loops through a sequence of switch specification, peer secret entry, and local secret entry. To exit the
loop, press Enter for the switch name; then type y.
switchA:admin> secauthsecret --set
This command is used to set up secret keys for the DH-CHAP authentication.
The minimum length of a secret key is 8 characters and maximum 40
characters. Setting up secret keys does not initiate DH-CHAP
authentication. If switch is configured to do DH-CHAP, it is performed
whenever a port or a switch is enabled.
Warning: Please use a secure channel for setting secrets. Using
an insecure channel is not safe and may compromise secrets.
Following inputs should be specified for each entry.
1. WWN for which secret is being set up.
2. Peer secret: The secret of the peer that authenticates to peer.
3. Local secret: The local secret that authenticates peer.
Press Enter to start setting up shared secrets > <cr>
Enter WWN, Domain, or switch name (Leave blank when done): 10:20:30:40:50:60:70:80
Enter peer secret: <hidden>
Re-enter peer secret: <hidden>
Enter local secret: <hidden>
Re-enter local secret: <hidden>
Enter WWN, Domain, or switch name (Leave blank when done): 10:20:30:40:50:60:70:81
Enter peer secret: <hidden>
Re-enter peer secret: <hidden>
Enter local secret: <hidden>
Re-enter local secret: <hidden>
Enter WWN, Domain, or switch name (Leave blank when done): <cr>
Are you done? (yes, y, no, n): [no] y
Saving data to key store... Done.
3.
Disable and enable the ports on a peer switch using the portDisable and portEnable
commands.

Fabric wide distribution of the Auth policy

The AUTH policy can be manually distributed to the fabric using the distribute command; there is no
support for automatic distribution. Since this policy is distributed manually, you cannot set fabric-wide
consistency policy (fddcfg –-fabwideset) for automatic fabric-wide distribution.
To distribute the AUTH policy, see
set".
--
"To distribute the local ACL
policies:" on page 124 for instructions.
Fabric OS 6.x administrator guide 115

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ae370a - brocade 4gb san switch 4/12

Table of Contents