User guide
Browser, OS, and Java plug-in support18
Security: HTTP policy If HTTP_Policy is empty, you will not be able to log in and will receive a
Page not found error. This is expected behavior for this policy.
Security: invalid
certificate
Web Tools and Fabric OS are not consistent in how they report switch
certificate status. Web Tools reports a valid certificate with extra
characters appended to it as invalid, whereas Fabric OS accepts the
certificate and allows a secmodeenable command to complete
successfully.
Security: PKICERT
utility, CSR syntax
Before using the PKICERT utility to prepare a certificate signing request
(CSR), ensure that there are no spaces in the switch names of any switches
in the fabric. The web site that processes the CSRs and generates the
digital certificates does not accept switch names containing spaces; CSRs
that do not conform to this requirement are rejected.
Security: PKICERT
utility, installing
certificates
PKICERT v1.0.6 is the most current version of the PKICERT utility.
When running the PKICERT utility to install switch certificates in a fabric
that did not previously contain switch certificates and now includes a SAN
Director 2/128, select the option to specify that certificates are installed
only on those switches that do not currently contain certificates. SAN
Director 2/128s are delivered with switch certificates preinstalled.
Switches that were originally shipped with Fabric OS v2.5, v3.0, and
v4.0 and have never installed and enabled Secure Fabric OS do not have
certificates installed.
If you need to reinstall switch certificates in a SAN Director 2/128, follow
these guidelines:
• The host running PKICERT 1.0.6 must be connected to a proxy switch
running Fabric OS v2.6.2, v3.1.2, or v4.2.
• All switches in the fabric other than the SAN Director 2/128 can run
v2.6.1, v3.1, v4.1 or newer firmware.
Security: selectelnet If you try to log in to a switch through a sectelnet client while that switch is
in the process of either booting or shutting down, you might see the
message, Random number generation failed. The message is printed by
the sectelnet client because the switch Telnet service is not running (the
service has either already been shut down, if the switch is shutting down,
or is not yet established, if the switch is booting). If the switch is booting,
wait a few seconds and try again.
Table 4 Fabric OS area information (continued)
Fabric OS Area Description