HP StorageWorks 2/16V Brocade Fabric Manager Administrator's Guide (53-1000019 - Page 196

Managing Administrative Domains, Requirements for Admin Domains

Page 196 highlights

12 Managing Administrative Domains The default truststore password is "password". Fabric Manager provides a set of command line utilities to manage the truststore. You can use these utilities to import, export, delete, and print trusted certificates. You can also change the default trusted password. importcert exportcert listcert printcert deletecert storepasswd Imports a certificate from a file and add it to the list of trusted certificates (truststore). Exports a certificate from the truststore to another file. Prints the contents of a truststore entry or the entire truststore file. Prints the contents of a certificate stored in a file other than the truststore. Deletes a truststore entry. Changes the default truststore password. The new password must be at least six characters long. Caution Use care when typing the password, as it is echoed (displayed exactly as typed). This is a limitation of the Java keytool. Fabric Manager supports certificate validation and extended hostname verification (if they are enabled). By default, both certificate validation and hostname verification are enabled. If certificate validation is enabled, switch connection is not established unless the certificate is issued by a trusted CA. If the switch certificate is not issued by a well-known CA (or one of the trusted CAs in the trusted certificate repository), the root certificate must be added to the trusted certificate repository. Managing Administrative Domains Using Administrative Domains (Admin Domains), you can partition the fabric into logical groups and allocate administration of these groups to different user accounts so that these accounts manage only the Admin Domains assigned to them and do not make changes to the rest of the fabric. You can create domains that are grouped together based on the type of members in the domain. For example, you can create Admin Domains based on the type of switches in your fabric using the WWN or domain ID (not to be confused with the Admin Domain number) or put all the devices in a particular department in the same Admin Domain for ease of administering those devices. You can have up to 256 Admin Domains in a fabric (254 user-defined and 2 system-defined), numbered from 0 through 255. Admin Domains are designated by a name and a number. This document refers to specific Admin Domains using the format "ADn" where n is a number between 0 and 255. See the Web Tools Administrator's Guide for additional information. Requirements for Admin Domains Admin Domains are supported on fabrics with switches running Fabric OS 5.2.0 and higher. You must have a valid Advanced Zoning license to use Admin Domains. 12-4 Fabric Manager Administrator's Guide Publication Number: 53-1000196-01-HP

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406

12-4
Fabric Manager Administrator’s Guide
Publication Number: 53-1000196-01-HP
Managing Administrative Domains
12
The default truststore password is “password”.
Fabric Manager provides a set of command line utilities to manage the truststore. You can use these
utilities to import, export, delete, and print trusted certificates. You can also change the default trusted
password.
Fabric Manager supports certificate validation and extended hostname verification (if they are enabled).
By default, both certificate validation and hostname verification are enabled.
If certificate validation is enabled, switch connection is not established unless the certificate is issued by
a trusted CA. If the switch certificate is not issued by a well-known CA (or one of the trusted CAs in the
trusted certificate repository), the root certificate must be added to the trusted certificate repository.
Managing Administrative Domains
Using Administrative Domains (Admin Domains), you can partition the fabric into logical groups and
allocate administration of these groups to different user accounts so that these accounts manage only the
Admin Domains assigned to them and do not make changes to the rest of the fabric.
You can create domains that are grouped together based on the type of members in the domain. For
example, you can create Admin Domains based on the type of switches in your fabric using the WWN
or domain ID (not to be confused with the Admin Domain number) or put all the devices in a particular
department in the same Admin Domain for ease of administering those devices.
You can have up to 256 Admin Domains in a fabric (254 user-defined and 2 system-defined), numbered
from 0 through 255. Admin Domains are designated by a name and a number. This document refers to
specific Admin Domains using the format “AD
n
” where
n
is a number between 0 and 255.
See the
Web Tools Administrator’s Guide
for additional information.
Requirements for Admin Domains
Admin Domains are supported on fabrics with switches running Fabric OS 5.2.0 and higher.
You must have a valid Advanced Zoning license to use Admin Domains.
importcert
Imports a certificate from a file and add it to the list of trusted certificates
(truststore).
exportcert
Exports a certificate from the truststore to another file.
listcert
Prints the contents of a truststore entry or the entire truststore file.
printcert
Prints the contents of a certificate stored in a file other than the truststore.
deletecert
Deletes a truststore entry.
storepasswd
Changes the default truststore password. The new password must be at least six
characters long.
Caution
Use care when typing the password, as it is echoed (displayed exactly as typed). This is a limitation of
the Java keytool.