EasyManuals Logo

HP SN3000B User Manual

HP SN3000B
584 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #563 background imageLoading...
Page #563 background image
Fabric OS Administrator’s Guide 525
53-1002446-01
FIPS mode configuration
C
Specify the DNS IP address using either IPv4 or IPv6. This address is needed for the switch to
resolve the domain name to the IP address because LDAP initiates a TCP session to connect to
your Microsoft Active Directory server. A Fully Qualified Domain Name (FQDN) is needed to
validate the server identity as mentioned in the common name of the server certificate.
3. Set the switch authentication mode and add your LDAP server by using the commands shown
in the following example. Provide the Fully Qualified Domain Name (FQDN) of the Microsoft
Active Directory server for the host name parameter while configuring LDAP.
Example of setting up LDAP for FIPS mode
switch:admin> aaaconfig --add GEOFF5.ADLDAP.LOCAL -conf ldap -d adldap.local
-p 389 -t 3
switch:admin> aaaconfig --authspec "ldap;local"
switch:admin> aaaconfig –show
RADIUS CONFIGURATIONS
=====================
RADIUS configuration does not exist.
LDAP CONFIGURATIONS
===================
Position : 1
Server : GEOFF5.ADLDAP.LOCAL
Port : 389
Domain : adldap.local
Timeout(s) : 3
Primary AAA Service: LDAP
Secondary AAA Service: Switch database
4. Set up LDAP according to the instructions in “LDAP configuration and Microsoft Active
Directory” on page 109, and then perform the following additional Microsoft Active Directory
settings
a. To support FIPS-compliant TLS cipher suites on the Microsoft Active Directory server, allow
the SCHANNEL settings listed in Table 88.
b. Enable the FIPS algorithm policy on the Microsoft Active Directory.
TABLE 88 Active Directory keys to modify
Key Sub-key
Ciphers 3DES
Hashes SHA1
Key exchange algorithm PKCS
Protocols TLSv1.0

Table of Contents

Other manuals for HP SN3000B

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP SN3000B and is the answer not in the manual?

HP SN3000B Specifications

General IconGeneral
BrandHP
ModelSN3000B
CategorySwitch
LanguageEnglish

Related product manuals