HP StorageWorks 8/20q HP StorageWorks 8/20q Fibre Channel Switch command line - Page 157

PrimarySecret, SecondaryHash, SHA-1, SecondarySecret, Secret, Binding, FabricBindingEnabled

Page 157 highlights

Table 13 Group member attributes (continued) Attribute PrimarySecret (ISL and Port Groups) SecondaryHash (ISL and Port Groups) SecondarySecret (ISL and Port Groups) Secret (MS Groups) Binding (ISL Groups) Description Hexadecimal string that is encrypted by the primary hash for authentication with the member. The string has the following lengths depending on the primary hash function: • MD5 hash: 16-byte • SHA-1 hash: 20-byte Hash function to use to decipher the encrypted secondary secret sent by the group member. Hash values are MD5 or SHA-1. The secondary hash is used when the primary hash is not available on the group member. The primary hash and the secondary hash cannot be the same. Hex string that is encrypted by the secondary hash and sent for authentication. The string has the following lengths, depending on the secondary hash function: • MD5 hash: 16-byte • SHA-1 hash: 20-byte Hexadecimal string that is encrypted by the hash function for authentication with MS group members. The string has the following lengths depending on the hash function: • MD5 hash: 16-byte • SHA-1 hash: 20-byte Domain ID of the switch to which to bind the ISL group member worldwide name. This option is available only if FabricBindingEnabled is set to True using the set config security command. 0 (zero) specifies no binding. Operands list Displays a list of all groups and the security sets of which they are members. This operand is available without an Admin session. members [group] Displays all members of the group given by [group]. This operand is available without an Admin session. remove [group] [member_list] Remove the port/device worldwide name given by [member] from the group given by [group]. Use a to delimit multiple member names in [member_list] rename [group_old] [group_new] Renames the group given by [group_old] to the group given by [group_new]. securitysets [group] Displays the list of security sets of which the group given by [group] is a member. This operand is available without an Admin session. type [group] Displays the group type for the group given by [group]. This operand is available without an Admin session. Notes Primary and secondary secrets are not included in a switch configuration backup. Therefore, after restoring a switch configuration, you must re-enter the primary and secondary secrets. Otherwise, the switch will isolate because of an authentication failure. For more information about managing groups in security sets, see the securityset command. 8/20q Fibre Channel Switch command line interface guide 157

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332

8/20q Fibre Channel Switch command line interface guide
157
PrimarySecret
(ISL and Port Groups)
Hexadecimal string that is encrypted by the primary hash for
authentication with the member. The string has the following lengths
depending on the primary hash function:
MD5 hash: 16-byte
SHA-1 hash: 20-byte
SecondaryHash
(ISL and Port Groups)
Hash function to use to decipher the encrypted secondary secret sent
by the group member. Hash values are
MD5
or
SHA-1
. The
secondary hash is used when the primary hash is not available on
the group member. The primary hash and the secondary hash cannot
be the same.
SecondarySecret
(ISL and Port Groups)
Hex string that is encrypted by the secondary hash and sent for
authentication. The string has the following lengths, depending on the
secondary hash function:
MD5 hash: 16-byte
SHA-1 hash: 20-byte
Secret
(MS Groups)
Hexadecimal string that is encrypted by the hash function for
authentication with MS group members. The string has the following
lengths depending on the hash function:
MD5 hash: 16-byte
SHA-1 hash: 20-byte
Binding
(ISL Groups)
Domain ID of the switch to which to bind the ISL group member
worldwide name. This option is available only if
FabricBindingEnabled
is set to True using the
set config security
command. 0 (zero) specifies no binding.
Table 13
Group member attributes
(continued)
Attribute
Description
Operands
list
Displays a list of all groups and the security sets of which they are members. This operand is
available without an Admin session.
members [group]
Displays all members of the group given by [group]. This operand is available without an Admin
session.
remove [group] [member_list]
Remove the port/device worldwide name given by [member] from the group given by [group].
Use a <space> to delimit multiple member names in
[member_list]
rename [group_old] [group_new]
Renames the group given by [group_old] to the group given by [group_new].
securitysets [group]
Displays the list of security sets of which the group given by [group] is a member. This operand is
available without an Admin session.
type [group]
Displays the group type for the group given by [group]. This operand is available without an
Admin session.
Notes
Primary and secondary secrets are not included in a switch configuration backup. Therefore, after
restoring a switch configuration, you must re-enter the primary and secondary secrets. Otherwise, the
switch will isolate because of an authentication failure.
For more information about managing groups in security sets, see the
securityset
command.