EasyManuals Logo

HPE FlexNetwork 5510 HI Series Security Configuration Guide

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #231 background imageLoading...
Page #231 background image
218
• If you do not assign the key pair a name, the system assigns the default name to the key pair
and marks the key pair as default. You can also assign the default name to another key pair, but
the system does not mark the key pair as default. The name of a key pair must be unique
among all manually named key pairs that use the same key algorithm. If a name conflict occurs,
the system asks whether you want to overwrite the existing key pair.
• The key pairs are automatically saved and can survive system reboots.
Table 18 A comparison of different types of key algorithms
Type Number of key pairs Modulus length
RSA
• In non-FIPS mode:
ï‚¡ One host key pair, if you specify a key pair name.
ï‚¡ One server key pair and one host key pair, if you
do not specify a key pair name.
Both key pairs use their default names.
• In FIPS mode: One host key pair.
NOTE:
Only SSH 1.5 uses the RSA server key pair.
• In non-FIPS mode:
512 to
2048 bits, 1024 bits by
default.
To ensure security, use a
minimum of 768 bits.
• In FIPS mode: 2048 bits.
DSA One host key pair.
• In non-FIPS mode:
512 to
2048 bits, 1024 bits by
default.
To ensure security, use a
minimum of 768 bits.
• In FIPS mode: 2048 bits.
ECDSA One host key pair.
• In Release 1111: 192 bits.
• In Release 1121 and later:
ï‚¡ In non-
FIPS mode: 192
bits, 256 bits, 384 bits, or
521 bits.
ï‚¡ In FIPS mode: 256 bits,
384 bits, or 521 bits.
To create a local key pair:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Create a local key pair.
In Release 1111:
public-key local create
{
dsa
|
ecdsa
|
rsa
} [
name
key-name ]
In Release 1121 and later:
• In non-FIPS mode:
public-
key local create
{ dsa | ecdsa [ secp192r1 |
secp256r1 | secp384r1 |
secp521r1 ] | rsa } [ name
key-name ]
• In FIPS mode:
public-
key local create
{ dsa | ecdsa [ secp256r1 |
secp384r1 | secp521r1 ] |
rsa
} [
name
key-name ]
By default, no local key pairs exist.

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5510 HI Series and is the answer not in the manual?

HPE FlexNetwork 5510 HI Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5510 HI Series
CategorySwitch
LanguageEnglish

Related product manuals