The Firmwaredownload Command - HP SN3000B Administrator's Manual

Brocade fabric os administrator's guide - supporting fabric os v7.0.1 (53-1002446-01, march 2012)
Hide thumbs Also See for SN3000B:
Table of Contents

Advertisement

NOTE
If FIPS is enabled, all logins should be done through SSH or direct serial and the transfer protocol
should be SCP.
Updating the firmware key
1. Log in to the switch as admin.
2. Type the firmwareKeyUpdate command and respond to the prompts.

The firmwareDownload command

As mentioned previously, the public key file needs to be packaged, installed, and run on your switch
before downloading a signed firmware.
When firmwareDownload installs a firmware file, it needs to validate the signature of the file.
Different scenarios are handled as follows:
SAS, DMM, and third party application images are not signed.
Configuring the switch for signed firmware
1. Connect to the switch and log in using an account with admin permissions.
2. Type the configure command.
3. Respond to the prompts as follows:
Fabric OS Administrator's Guide
53-1002446-01
If a firmware file does not have a signature, how it is handled depends on the
"signed_firmware" parameter on the switch. If it is enabled, firmwareDownload fails.
Otherwise, firmwareDownload displays a warning message and proceeds normally. So
when downgrading to a non-FIPS compliant firmware, the "signed_firmware" flag needs to
be disabled.
If the firmware file has a signature but the validation fails, firmwareDownload fails. This
means the firmware is not from Brocade, or the contents have been modified.
If the firmware file has a signature and the validation succeeds, firmwareDownload
proceeds normally.
System Service Default is no; press Enter to select default setting.
ssl attributes
Default is no; press Enter to select default setting.
snmp
Default is no; press Enter to select default setting.
attributes
rpcd attributes Default is no; press Enter to select default setting.
cfgload
Select Yes. The following questions are displayed:
attributes
Enforce secure config Upload/Download: Select yes
Enforce signed firmware download: Select yes
Webtools
Default is no; press Enter to select default setting.
attributes
System
Default is no; press Enter to select default setting.
9
FIPS support
203

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os v7.0.1

Table of Contents