HP StorageWorks 8/80 HP StorageWorks Fabric OS 6.1.x administrator guide (5697 - Page 185

Updating the firmwarekey

Page 185 highlights

The switch manufacturer generates one private and public key pair. These key pairs are stored in the privatekey.pem and pubkey.pem files, respectively. The private key file is used to sign the firmware files. The public key file is packaged in an RPM-package as part of the firmware, and will be downloaded to the switch. After it is downloaded, it can be used to validate the firmware to be downloaded next time. The public key file on the switch contains only one public key. It is only able to validate firmware signed using one corresponding private key. If the private key changes in the future releases, you change the public key on the switch by one of the following method: a. By using firmwareDownload. If the public key file on the switch has not been modified after it is installed, when a new firmware is downloaded, firmwareDownload always replaces the public key file on the switch with what is in the new firmware. This allows you to have planned firmware key changes. b. By using the firmwarekey command. This command retrieves a specified public key file from a specific server location and replaces the one on the switch. c. Refer to the latest Fabric OS release notes for information regarding firmware versions and their corresponding public key files If the public key file has been modified using the firmwarekey command, firmwareDownload will not replace this file in the subsequent downloads because it thinks the change is intentional. The user will need to use the firmwarekey command for subsequent updates of this file. A different firmware key pair will be created for digitally signed firmware releases. The private key file for the digitally signed firmware releases will be used to sign released firmware, and the public key file will be packaged inside these digitally signed firmware releases. NOTE: If FIPS is enabled, all logins should be done through SSH or direct serial and the transfer protocol should be SCP. Updating the firmwarekey To update the firmwarekey: 1. Log in to the switch as admin. 2. Type the firmwarekeyupdate command. 3. Respond to the prompts as follows: Server Name Enter the name or IP address of the FTP server, or SSH server for SCP, where or IP Address the firmwarekey file is stored; for example, 192.1.2.3. Download from USB Optional: -U (upper case) Specify this option if you want to download from the USB device attached to the active CP. Network protocol Specify the file transfer protocol used to download the firmware from the file server. Valid values are FTP and SCP. The Values are not case-sensitive. If "-p" is not specified, firmwarekeyupdate will determine the protocol automatically by checking the config.security parameter on the switch. User name Enter the user name of your account on the server; for example, "JaneDoe". File name Specify the fully qualified path name of the firmware directory, for example, /pub/firmwarekey/pubkey.pem,12345. Absolute path names may be specified using forward slashes (/). Password Enter a password. This operand can be omitted if firmware is accessible through USB or if no password is required by the FTP server. This operand is required when accessing an SSH server. Fabric OS 6.1.x administrator guide 185

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492

Fabric OS 6.1.x administrator guide
185
The switch manufacturer generates one private and public key pair. These key pairs are stored in the
privatekey.pem and pubkey.pem files, respectively. The private key file is used to sign the firmware files. The
public key file is packaged in an RPM-package as part of the firmware, and will be downloaded to the
switch. After it is downloaded, it can be used to validate the firmware to be downloaded next time.
The public key file on the switch contains only one public key. It is only able to validate firmware signed
using one corresponding private key. If the private key changes in the future releases, you change the
public key on the switch by one of the following method:
a.
By using
firmwareDownload
. If the public key file on the switch has not been modified after it is
installed, when a new firmware is downloaded,
firmwareDownload
always replaces the public
key file on the switch with what is in the new firmware. This allows you to have planned firmware
key changes.
b.
By using the
firmwarekey
command.
This command retrieves a specified public key file from a
specific server location and replaces the one on the switch.
c.
Refer to the latest
Fabric OS release notes
for information regarding firmware versions and their
corresponding public key files
If the public key file has been modified using the firmwarekey command,
firmwareDownload
will
not replace this file in the subsequent downloads because it thinks the change is intentional. The
user will need to use the
firmwarekey
command for subsequent updates of this file.
A different firmware key pair will be created for digitally signed firmware releases. The private key file for
the digitally signed firmware releases will be used to sign released firmware, and the public key file will be
packaged inside these digitally signed firmware releases.
NOTE:
If FIPS is enabled, all logins should be done through SSH or direct serial and the transfer protocol
should be SCP.
Updating the firmwarekey
To update the firmwarekey:
1.
Log in to the switch as admin.
2.
Type the
firmwarekeyupdate
command.
3.
Respond to the prompts as follows:
Server Name
or IP Address
Enter the name or IP address of the FTP server, or SSH server for SCP, where
the firmwarekey file is stored; for example, 192.1.2.3.
Download
from USB
Optional: -U (upper case)
Specify this option if you want to download from
the USB device attached to the active CP.
Network
protocol
Specify the file transfer protocol used to download the firmware from the file
server. Valid values are FTP and SCP. The Values are not case-sensitive. If
“-p” is not specified,
firmwarekeyupdate
will determine the protocol
automatically by checking the config.security parameter on the switch.
User name
Enter the user name of your account on the server; for example, “JaneDoe”.
File name
Specify the fully qualified path name of the firmware directory, for example,
/pub/firmwarekey/pubkey.pem,12345.
Absolute path names may be
specified using forward slashes (/).
Password
Enter a password. This operand can be omitted if firmware is accessible
through USB or if no password is required by the FTP server. This operand is
required when accessing an SSH server.