Hp Secure Key Manager Uživatelský manuál Strana 217

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 327
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 216
Table 111 Remote Administration Settings section components
Components Description
Web Admin
Server IP
TheWebAdminServerIPaddressisthelocalIPaddressusedtocongure the SKM via
the Management
Console.Youcanselectonespecic IP address or you can select all
of the IP addresses bound to the SKM. The URL used to connect to the Management
Console is: ht
tps://IP-address:port.
CAUTION:
We strongly recommend that you limit the Web Admin Server IP to a specicIP
address. If you have four IP addresses bound to the SKM, and you select All
instead of a specic IP address, then the SKM listens for Web Administration
requests on f
our different IP addresses; whereas, if you specify a single IP address,
the SKM liste
ns for Web Administration requests on only one IP address. This can
greatly reduce system vulnerability to outside attacks.
Web Admin
Server Port
The Web Admin
Server Port species the port on which the server listens for requests.
The default
port is 9443.
Web Admin
Client Certicate
Authentication
The Web Admin Client Certicate Authentication setting activates the Management
Console Client Authentication feature, which requires that users present a client
certicate when logging into the Management Console.
CAUTION:
This feature is immediately enabled when you select this checkbox. If you select
this option through the Management Console, you will be immediately logged
off and will need a valid client certicate to return. If needed, you can use the
editrassettingscommandfromtheCLItodisablethisfeaturewithoutpresenting
acerticate. For more information on this feature, see Remote Administration
Procedures.
Web Admin
Trusted CA List
Prole
This eld allows you to select a prole to use to verify that client certicates are signed
by a CA trusted by the SKM appliance. This option is only valid if you require clients to
provide a certicate to authenticate to the KMS Server.
As delivered, the default Trusted CA List prole contains no CAs. You must either add
CAs to the default prole or create a new prole and populate it with at least one
trusted CA before the KMS Server can authenticate client certicates
SSH Adm
in Server
IP
TheSSHAdminServerIPaddressistheIPaddressusedtocongure the SKM from the
CLI. You can select one specic IP address or all of the IP addresses bound to the SKM.
CAUTION:
We strongly recommend that you limit the SSH Admin Server IP to a specicIP
address. If you have four IP addresses bound to the SKM, and you select All
instead of a specic IP address, then the SKM listens for SSH Administration
requests on four different IP addresses; whereas, if you specify a single IP address,
the SKM listens for SSH Administration requests on only one IP address. This can
greatly reduce system vulnerability to outside attacks.
SSH Admin Server
Port
The SSH Administration Server Port species the port on which the server listens for
requests. The default port is 22.
Edit
Click Edit tomodifytheremoteadministratorsettings.
Recreate Web Cert
Click Recreate Web Cert to generate a new certicate for the remote administration
Management Console. After you click Recreate Web Cert,youarepresentedwithan
intermediate page that allows you to specify the duration of the Web Admin Certicate.
After you specify a value in days, click Create. You must close all browser windows
and restart the browser to reconnect to the Management Console.
Recreate SSH Key
Click Recreate SSH Key to generate a new key for remote administration use via SSH.
Recreating the key closes all active SSH connections.
Secure Key Manager
217
Zobrazit stránku 216
1 2 ... 212 213 214 215 216 217 218 219 220 221 222 ... 326 327

Komentáře k této Příručce

Žádné komentáře