HP XP20000/XP24000 HP StorageWorks XP24000/XP20000 Remote Web Console User Gui - Page 15

The Year 2010 Encryption Problem, Single Sign-on from HP Systems Insight Manager

Page 15 highlights

version. If the Advanced Security Mode is enabled, do not perform the account update operation on the version that was downgraded to the previous version. • If the Advanced Security Mode is enabled, HP recommends using a certificate for the SSL-encrypted communication with the hash function larger than SHA-2 (SHA-256 or larger). The Year 2010 Encryption Problem The National Institute of Standards and Technology (NIST) compiles the types of encryption that U.S. government agencies should use. The NIST recommends transitioning to encryption types with larger key size and advanced security after 2010. Although responding to this issue is not mandatory, it is recommended. A large number of devices and systems utilizing encryption will be affected by this new encryption standard. Single Sign-on from HP Systems Insight Manager Remote Web Console supports single sign-on from HP Systems Insight Manager. A user who logs in to HP Systems Insight Manager can operate the Remote Web Console main window by clicking Remote Web Console in the Tool menu of HP Systems Insight Manager. The user is not required to enter a user ID and password into Remote Web Console, because the user is already logged in to HP Systems Insight Manager. To implement single sign-on using HP Systems Insight Manager, you need to import a Remote Web Console tool definition file into HP Systems Insight Manager, and register certificates for HP Systems Insight Manager to the SVP. For details on how to import a tool definition file, see "Importing a Tool Definition File into HP Systems Insight Manager" (page 115). For details on how to register certificates, see "Registering the Certificates of HP Systems Insight Manager" (page 116). All users who are allowed to log in to HP Systems Insight Manager can also log in to Remote Web Console. The operation privilege (role) for Remote Web Console depends on what kind of operation privileges the user has when the user logs in to HP Systems Insight Manager (see Table 4 (page 15)). Table 4 Operation Privileges for Remote Web Console after Single Sign-on from HP Systems Insight Manager Role for HP Systems Insight Manager Role for Remote Web Console Account administrator Audit log role administrator role Storage administrator Operation privilege for role each function1 Administrator Modify Modify Enable Modify (for all functions) Operator Disable Modify Enable Modify (for all functions) User Disable View Enable View (for all functions) 1 User accounts registered to HP Systems Insight Manager are not allowed to set the operation privilege for each function of program product options. Single Sign-on from HP Systems Insight Manager 15

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151

version. If the
Advanced Security Mode
is enabled, do not perform the account update
operation on the version that was downgraded to the previous version.
If the
Advanced Security Mode
is enabled, HP recommends using a certificate for the
SSL-encrypted communication with the hash function larger than SHA-2 (SHA-256 or larger).
The Year 2010 Encryption Problem
The National Institute of Standards and Technology (NIST) compiles the types of encryption that
U.S. government agencies should use. The NIST recommends transitioning to encryption types with
larger key size and advanced security after 2010. Although responding to this issue is not
mandatory, it is recommended. A large number of devices and systems utilizing encryption will
be affected by this new encryption standard.
Single Sign-on from HP Systems Insight Manager
Remote Web Console supports single sign-on from HP Systems Insight Manager. A user who logs
in to HP Systems Insight Manager can operate the Remote Web Console main window by clicking
Remote Web Console
in the
Tool
menu of HP Systems Insight Manager. The user is not required to
enter a user ID and password into Remote Web Console, because the user is already logged in
to HP Systems Insight Manager. To implement single sign-on using HP Systems Insight Manager,
you need to import a Remote Web Console tool definition file into HP Systems Insight Manager,
and register certificates for HP Systems Insight Manager to the SVP. For details on how to import
a tool definition file, see
“Importing a Tool Definition File into HP Systems Insight Manager”
(page 115)
. For details on how to register certificates, see
“Registering the Certificates of HP Systems
Insight Manager” (page 116)
.
All users who are allowed to log in to HP Systems Insight Manager can also log in to Remote Web
Console. The operation privilege (role) for Remote Web Console depends on what kind of operation
privileges the user has when the user logs in to HP Systems Insight Manager (see
Table 4 (page
15)
).
Table 4 Operation Privileges for Remote Web Console after Single Sign-on from HP Systems Insight
Manager
Role for Remote Web Console
Role for HP Systems
Insight Manager
Operation privilege for
each function
1
Storage administrator
role
Audit log
administrator role
Account administrator
role
Modify (for all
functions)
Enable
Modify
Modify
Administrator
Modify (for all
functions)
Enable
Modify
Disable
Operator
View (for all functions)
Enable
View
Disable
User
1
User accounts registered to HP Systems Insight Manager are not allowed to set the operation privilege for each function
of program product options.
Single Sign-on from HP Systems Insight Manager
15