HP 3PAR OS 2.3.1 MU5 Patch 35 Release Notes (QL226-97099)

1.6 CLI Client
The CLI client now prompts you for a new SSL certificate when connecting to HP 3PAR Storage System.
When accepting a new SSL certificate, you can save its information in the exception file. Once the
information is saved, CLI client will connect to the same HP 3PAR Storage System without prompting.
You can choose the directory where the exception file is created by the certdir option or by the
TPDCERTDIR environment variable. The default is $HOME/.hp3par on Unix–based systems and
%USERPROFILE%\.hp3par on Windows–based systems. The file name is excp. When saving the
information about the certificate, you should check the validity of the expiration date. Although an
expired certificate can be saved at your discretion, there will never be another prompt for the expiration
of the certificate.
You can also save the entire SSL certificate in the certificate file in Privacy Enhanced Mail (PEM) format
before establishing a secure connection. Use the showcert command with the pem option to export
the SSL certificate in PEM format. You can specify the certificate file by the certfile option or by
the TPDCERTFILE environment variable. The default is $HOME/.hp3par/cert on Unix–based
systems and %USERPROFILE%\.hp3par\cert on Windows–based systems.
Prompt from CLI client may not be desired for batch programs that execute CLI client without human
interaction. You can use the -nocertprompt option or TPDNOCERTPROMPT environment variable
to suppress prompt and force CLI client fail with an error message when the SSL certificate is not
validated.
Information about -certdir, -certfile, and -nocertprompt options, and TPDCERTDIR,
TPDCERTFILE, and TPDNOCERTPROMPT environment variables can be viewed by executing cli
-h.
Existing CLI clients continue to work with HP 3PAR Storage System after the installation of Patch 35.
They will not attempt to validate a new SSL certificate.
1.7 Other Upgrades
In addition to this patch, the following host client applications must also be installed to complete the
upgrade of HP 3PAR StoreServ.
1.7.1 Management Console
Management Console version 4.4.2 displays the SSL certificate upon connecting to the HP 3PAR
Storage System and requires you to confirm the certificate. If you accept the SSL certificate, it is cached
and you will no longer see the certificate again on a subsequent connection.
NOTE: Management Console version 4.4.1 and earlier will not be able to connect to the HP 3PAR
Storage System using Secure Connection after the installation of Patch 35.
NOTE: Management Console 4.4.2 will support StorServ systems without Patch 35.
1.7.2 HP 3PAR Cluster Extension for Windows (CLX)
For existing CLX customers:
Every Microsoft failover cluster node must upgrade the existing 3PAR CLI to 3PAR CLI 2.3.1 MU5
P35.
For existing customers of CLX running either one of CLX versions 1.00.00 or 2.00.00 or 3.00.00
or 3.01.00 must upgrade to CLX 3.02.00. Refer to the CLX Installation Guide at the HP 3PAR
Cluster Extension Manuals page for upgrade procedures.
Refer to CLX Installation Guide at the HP 3PAR Cluster Extension Manuals page to perform the
CLX configuration after the CLX upgrade is completed on all the failover cluster nodes.
6 1.6 CLI Client