HP StorageWorks 8/80 HP StorageWorks Fabric OS 6.1.x administrator guide (5697 - Page 184

Director restrictions for downgrading, FIPS Support

Page 184 highlights

v6.0.1\ 381MB 2007 Oct 19 10:39 config\ 0B 2007 Sep 28 15:33 support\ 0B 2007 Sep 28 15:33 firmwarekey\ 0B 2007 Sep 28 15:33 Available space on usbstorage 79% Downloading the 6.1.0 image using the relative path To download the 6.1.0 image using the relative path: 1. Log in to the switch as admin. 2. Type the firmwareDownload command with the -U operand: admin>firmwaredownload -U v6.1.0 Downloading the 6.1.0 image using the absolute path To download the 6.1.0 image using the absolute path: 1. Log in to the switch as admin. 2. Type the firmwareDownload command with the -U operand: admin>firmwaredownload -U /usb/usbstorage/brocade/firmware/v6.1.0 Director restrictions for downgrading Note the following restrictions: • 4/256 SAN Director with one or more FR4-18i blades: If you are running 5.1.0 firmware, then you cannot downgrade to earlier versions without removing the blades. • 4/256 SAN Director with one or more FC4-48 or FC4-16IP blades: If you are running Fabric OS 5.2.0, then you cannot downgrade to earlier versions without removing the blades. • Do not remove blades until the EX_Ports are removed first. The firmwareDownload command will indicate when the blades are safe to remove. • 4/256 SAN Director with one or more FC10-6 blades: If you are running Fabric OS 6.0.0b, then you cannot downgrade to earlier versions without removing the blades. • 4/256 SAN Director with one or more FC8-16 blades: If you are running Fabric OS 6.0.0b, then you cannot downgrade to earlier versions without removing the blade. • DC Director with FC8-16/32/48 blades: If you are running Fabric 6.0.0b, then you cannot downgrade to earlier versions of Fabric OS as they are not supported on this Director. FIPS Support Federal information processing standards (FIPS) specify the security standards needed to satisfy a cryptographic module utilized within a security system for protecting sensitive information in the computer and telecommunication systems. For more information about FIPS, refer to "Configuring advanced security features" on page 17. The 6.1.x firmware is digitally signed using the OpenSSL utility to provide FIPS support. In order to use the digitally signed software, you need to configure the switch to enable Signed Firmwaredownload. If it is not enabled then the firmware download process will ignore the firmware signature and work as before. If signed firmwaredownload is enabled, and if the validation succeeds, the firmware download process will proceed normally. If the firmware is not signed or if the signature validation fails, firmwareDownload will fail. To enable or disable FIPS, refer to "Configuring advanced security features" on page 17. Public and private key management For signed firmware, we use RSA with 1024-bit length key pair. The Fabric OS requires a private key to sign the firmware files. During firmwareDownload, the process requires the public key to validate the signatures of the firmware files. So the public key needs to be stored on the switch beforehand. The following describes how the key pairs will be managed for the current and future releases. 184 Installing and maintaining firmware

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492

184
Installing and maintaining firmware
v6.0.1\
381MB
2007 Oct 19 10:39
config\
0B
2007 Sep 28 15:33
support\
0B
2007 Sep 28 15:33
firmwarekey\
0B
2007 Sep 28 15:33
Available space on usbstorage 79%
Downloading the 6.1.0 image using the relative path
To download the 6.1.0 image using the relative path:
1.
Log in to the switch as admin.
2.
Type the
firmwareDownload
command with the -U operand:
admin>firmwaredownload –U v6.1.0
Downloading the 6.1.0 image using the absolute path
To download the 6.1.0 image using the absolute path:
1.
Log in to the switch as admin.
2.
Type the
firmwareDownload
command with the -U operand:
admin>firmwaredownload –U /usb/usbstorage/brocade/firmware/v6.1.0
Director restrictions for downgrading
Note the following restrictions:
4/256 SAN Director with one or more FR4-18i blades:
If you are running 5.1.0 firmware,
then you cannot downgrade to earlier versions without removing the blades.
4/256 SAN Director with one or more FC4-48 or FC4-16IP blades:
If you are running
Fabric OS 5.2.0, then you cannot downgrade to earlier versions without removing the blades.
Do not remove blades until the EX_Ports are removed first. The
firmwareDownload
command will
indicate when the blades are safe to remove.
4/256 SAN Director with one or more FC10-6 blades:
If you are running Fabric OS 6.0.0b,
then you cannot downgrade to earlier versions without removing the blades.
4/256 SAN Director with one or more FC8-16 blades:
If you are running Fabric OS 6.0.0b,
then you cannot downgrade to earlier versions without removing the blade.
DC Director with FC8-16/32/48 blades:
If you are running Fabric 6.0.0b, then you cannot
downgrade to earlier versions of Fabric OS as they are not supported on this Director.
FIPS Support
Federal information processing standards (FIPS) specify the security standards needed to satisfy
a
cryptographic module utilized within a security system for protecting sensitive information in the computer
and telecommunication systems. For more information about FIPS, refer to ”
Configuring advanced security
features
” on page 17.
The 6.1.x firmware is digitally signed using the OpenSSL utility to provide FIPS support. In order to use the
digitally signed software, you need to configure the switch to enable
Signed Firmwaredownload
. If it
is not enabled then the firmware download process will ignore the firmware signature and work as before.
If signed
firmwaredownload
is enabled, and if the validation succeeds, the firmware download process
will proceed normally. If the firmware is not signed or if the signature validation fails,
firmwareDownload
will fail.
To enable or disable FIPS, refer to ”
Configuring advanced security features
” on page 17.
Public and private key management
For signed firmware, we use RSA with 1024-bit length key pair. The Fabric OS requires a private key to
sign the firmware files. During
firmwareDownload
, the process requires the public key to validate the
signatures of the firmware files. So the public key needs to be stored on the switch beforehand. The
following describes how the key pairs will be managed for the current and future releases.