Destroying A Local Key Pair; Configuring A Peer Public Key - HPE FlexFabric 7900 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 7900 Series:
Table of Contents

Advertisement

Task
Display local RSA public keys.
Display local DSA public keys.
NOTE:
Do not distribute the RSA server public key serverkey (default) to a peer device.

Destroying a local key pair

To avoid key compromise, destroy the local key pair and generate a new pair after any of the
following conditions occurs:
An intrusion event has occurred.
The storage media of the device is replaced.
The local certificate has expired.
To destroy a local key pair:
Step
1.
Enter system view.
2.
Destroy a local key pair.

Configuring a peer public key

To encrypt information sent to a peer device or authenticate the digital signature of the peer device,
you must configure the public key of the peer device on the local device.
Table 6 Peer public key configuration methods
Method
Import the peer public key
from a public key file
(recommended)
Manually enter (type or copy)
the peer public key
For information about displaying or exporting host public keys, see
key."
Command
display public-key local rsa public [ name key-name ]
display public-key local dsa public [ name key-name ]
Command
system-view
public-key local destroy { dsa |
ecdsa | rsa } [ name key-name ]
Prerequisites
3.
Save the host public key in a file
on the peer device.
4.
Get the file from the peer
device, for example, by using
FTP or TFTP in binary mode.
Display and record the public key on
the peer device.
IMPORTANT:
If the peer device is an HPE device,
use the display public-key local
public command to display the
public key. The format of the public
key displayed in any other way might
be incorrect.
60
Remarks
N/A
N/A
Remarks
The system automatically converts
the imported public key to a string in
the Public Key Cryptography
Standards (PKCS) format.
If the key is not in the correct
format, the system discards the
key and displays an error
message. If the key is valid, for
example, the key displayed by
the display public-key local
public command, the system
saves the key.
Always use the first method if
you are not sure of the format of
the recorded public key.
"Distributing a local host public

Advertisement

Table of Contents
loading

Table of Contents