Ssh Enhancements - HP ProCurve 3500yl Release Notes

Software version k.13.49
Hide thumbs Also See for ProCurve 3500yl:
Table of Contents

Advertisement

Enhancements
Release K.13.16 Enhancements
Web and MAC authentications are not allowed on the same port if unauthenticated VLAN
(that is, a guest VLAN) is enabled for MAC authentication. An unauthenticated VLAN
can't be enabled for MAC authentication if Web and MAC authentication are both
enabled on the port.
Hitless re-authentication must be of the same type (MAC) that was used for the initial
authentication. Non-hitless re-authentication can be of any type.
The remaining Web/MAC functionality, including interactions with 802.1X, remains the same. Web
and MAC authentication can be used for different clients on the same port.
Normally, MAC authentication finishes much sooner than Web authentication. However, if Web
authentication should complete first, MAC authentication will cease even though it is possible that
MAC authentication could succeed. There is no guarantee that MAC authentication ends before Web
authentication begins for the client.
These changes are backward compatible with all existing user configurations.
Enhancement (PR_0000000088) — This enhancement provides new features for use with
SSH. The SSH enhancements are: AES encryption (included in the K.13.02 release). A new
configuration option is added to allow the server to specify the set of ciphers available for
client connection; A configurable key; Message Authentication Code (MAC) configuration.
A new configuration option provides the ability to configure which MACs a client is permitted
to use; Feedback information; and, SSH CLI show command information enhancements.

SSH Enhancements

Overview
The SSH enhancements are:
AES encryption (included in the K.13.02 release). A new configuration option is added
to allow the server to specify the set of ciphers available for client connection.
Configurable key
Message Authentication Code (MAC) configuration. A new configuration option
provides the ability to configure which MACs a client is permitted to use.
Feedback information
SSH CLI show command information enhancements
Specifying the Set of Ciphers
The following command allows you to specific which ciphers are available for a client to use for
connection. All ciphers are available by default; use the no form of the command to disable specific
ciphers.
105

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 8212zlProcurve 5400zl6200yl

Table of Contents