EasyManua.ls Logo

Hitachi SVP F 00 Series - Chapter 11: Setting Up SSL Encryption; About SSL; SSL Encryption of the Storage System

Hitachi SVP F 00 Series
275 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Chapter 11: Setting up SSL encryption
You can set up a Secure Sockets Layer (SSL) connection between the storage system and
the SVP.
SSL encrypts the Hitachi Device Manager - Storage Navigator user ID and password
exchanged between the storage system and SVP.
About SSL
SSL is a protocol for transmitting data securely over the Internet. Two SSL-enabled peers
use their private key and public key to establish a secure communication session, with
each peer encrypting transmitted data with a randomly generated and agreed-upon
symmetric key.
The following terms are associated with SSL:
Keypair: A keypair is two mathematically related cryptographic keys consisting of a
private key and its associated public key.
Server certicate: A server certicate forms an association between an identity (in this
case, the SVP server) and a specic public key and private key. A server certicate is
used to identify the SVP server to a client, so that the server and client can
communicate using SSL. Certicates can be self-signed or issued by a certicate
authority (CA). Self-signed certicates are generated by you, and the subject of the
certicate is the same as the issuer of the certicate. A client PC and SVP on an
internal LAN behind a rewall might provide sucient security. Certicates issued by
the CA are signed and trusted server certicates, where a Certicate Signing Request
(CSR) is sent to and certied by a trusted CA such as VeriSign. Using a certicate from
a CA provides higher reliability than a self-signed certicate, but is also more
expensive and can include several requirements.
SSL encryption of the storage system
The storage system uses SSL encryption for three connection paths. These paths are
designated A to C in the following table and gure.
Chapter 11: Setting up SSL encryption
Service Processor Technical Reference 197

Table of Contents

Related product manuals