Authentication-Algorithm - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Examples
# Create the IKE profile profile1.
<Sysname> system-view
[Sysname] ike profile profile1
# Enable AAA authorization. Specify the ISP domain abc and the username test.
[Sysname-ike-profile-profile1] aaa authorization domain abc username test

authentication-algorithm

Use authentication-algorithm to specify an authentication algorithm for an IKE proposal.
Use undo authentication-algorithm to restore the default.
Syntax
In non-FIPS mode:
authentication-algorithm { md5 | sha | sha256 | sha384 | sha512 | sm3 }
undo authentication-algorithm
In FIPS mode:
authentication-algorithm { sha| sha256 | sha384 | sha512 }
undo authentication-algorithm
Default
In non-FIPS mode, the IKE proposal uses the HMAC-SHA1 authentication algorithm.
In FIPS mode, the IKE proposal uses the HMAC-SHA256 authentication algorithm.
Views
IKE proposal view
Predefined user roles
network-admin
Parameters
md5: Specifies HMAC-MD5 as the authentication algorithm.
sha: Specifies HMAC-SHA1 as the authentication algorithm.
sha256: Specifies HMAC-SHA256 as the authentication algorithm.
sha384: Specifies HMAC-SHA384 as the authentication algorithm.
sha512: Specifies HMAC-SHA512 as the authentication algorithm.
sm3: Specifies HMAC-SM3 as the authentication algorithm.
The following matrix shows the sm3 keyword and hardware compatibility:
Hardware
MSR810/810-W/810-W-DB/810-LM/810-W-LM/810-10-PoE
/810-LM-HK/810-W-LM-HK/810-LMS/810-LUS
MSR2600-10-X1
MSR 2630
MSR3600-28/3600-51
MSR3600-28-SI/3600-51-SI
Keyword compatibility
Yes
No
Yes
Yes
Yes
574

Advertisement

Table of Contents
loading

Table of Contents