Do+Able Products 12347 Uživatelský manuál Strana 15

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 57
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 14
Hardware Management Console Best Practices
- 15 -
4.2 Secure WebSM
A secure WebSM connection using Secure Socket Layer (SSL) code is also
available on the HMC. The SSL code can also be downloaded as follows:
http://<HMC_hostname>/remote_client_security.html
The SSL protocol provides server authentication, data encryption and data
integrity. The HMC can be configured to require all clients to connect via SSL or
to give clients the option of connecting via SSL. The first option, required, is
more secure and therefore is preferred as a best practice. The HMC Security
Manager application, which can only be accessed by a system administrator with
super user authority and which must be configured at the console, controls these
options.
Secure WebSM uses the RSA public key cryptography algorithm. The user on
the client is authenticated to the server by his login password. The user name and
password are sent encrypted over the SSL socket. The SSL protocol protects
against changes or substitutions to data transmissions between the server and
client machines. All data transmissions between the server and client machines
are encrypted by the SSL protocol using the RSA RC4 algorithm with 128 bits
key used for bulk encryption, and 1024 bits key used in the key exchange of the
SSL protocol.
It’s important to understand that SSL encryption is not the default for WebSM
clients. It must be configured.
4.3 WebSM Ports
On the HMC, a WebSM server runs under xinetd control and listens on port 9090.
When a remote WebSM client connects to the HMC, the WebSM server first
authenticates the user ID and password. Once the authentication is completed, an
instance of a WebSM Server running a separate Java Virtual Machine will be
created. A pair of ports in the range of 30000 and 30009 is used as the
communications channel between this WebSM server and the remote WebSM
client.
Unless SSL encryption has been enabled as described above, the packets sent
between the client and the HMC are in clear text. Even when encryption is used in
the main WebSM client, a virtual terminal session to a partition opened from the
client is not encrypted because it uses a separate application.
Customers who choose not to use the remote management function can disable
the remote WebSM and Apache servers through the HMC Configuration menus
or by using the command chhmc.
Zobrazit stránku 14
1 2 ... 10 11 12 13 14 15 16 17 18 19 20 ... 56 57

Komentáře k této Příručce

Žádné komentáře