Preparing The Switch For Fips; Overview Of Steps - HP SN3000B Administrator's Manual

Brocade fabric os administrator's guide - supporting fabric os v7.0.1 (53-1002446-01, march 2012)
Hide thumbs Also See for SN3000B:
Table of Contents

Advertisement

Deleting an LDAP switch certificate
This procedure deletes the LDAP CA certificate from the switch.
1. Connect to the switch and log in using an account with admin permissions, or an account with
2. Enter the secCertUtil show -ldapcacert command to determine the name of the LDAP
3. Enter the secCertUtil delete -ldapcacert file_name command, where file_name is the name of

Preparing the switch for FIPS

It is important to prepare the switch for the following restrictions that exist in FIPS mode:
See
ATTENTION
You need the securityadmin and admin permissions to enable FIPS mode.

Overview of steps

Fabric OS Administrator's Guide
53-1002446-01
OM permissions for the PKI RBAC class of commands.
certificate file.
the LDAP certificate on the switch.
Example of deleting an LDAP CA certificate
switch:admin> seccertutil delete -ldapcacert swLdapca.pem
WARNING!!!
About to delete certificate: swLdapca.pem
ARE YOU SURE (yes, y, no, n): [no] y
Deleted LDAP certificate successfully
The root account and all root-only functions are not available.
HTTP, Telnet, RPC, and SNMP need to be disabled. Once these ports are blocked, you cannot
use them to read or write data from and to the switch.
The configDownload and firmwareDownload commands using an FTP server are blocked.
Table 87
on page 524 for a complete list of restrictions between FIPS and non-FIPS modes.
Remove legacy OpenSSH DSA keys.
Optional: Configure the RADIUS server or the LDAP server.
Optional: Configure any authentication protocols.
For LDAP only: Install an SSL certificate on the Microsoft Active Directory server and a CA
certificate on the switch for using LDAP authentication.
Ensure no filter policy rule permits access from Telnet, HTTP, or RPC.
Create separate IP filter policies for IPv4 and IPv6 and block access to Telnet (TCP port 23),
HTTP (TCP port 80), or RPC (TCP and UDP ports 897 and 898).
Undefined ports are blocked implicitly in FIPS mode.
Set the SNMP security level to off.
Disable the Boot PROM access.
Configure the switch for signed firmware.
Preparing the switch for FIPS
C
527

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SN3000B and is the answer not in the manual?

This manual is also suitable for:

Fabric os v7.0.1

Table of Contents

Save PDF