HP System Management Homepage User Guide, May 2005
This configuration leaves the default SP2 security enhancements intact, but will allow traffic over
the ports indicated above. These ports are required for HP Systems Insight Manager and Version
Control Repository Manager to run. Ports 2301 and 2381 are required for the Version Control
Repository Manager and ports 280 and 50000 are required by HP Systems Insight Manager. The
secure and insecure ports must be added for each product to enable proper communication with
the applications.
Why can I not import X.509 certificates directly into System Management
Homepage?
Solution: System Management Homepage generates Certificate Request in Base64 encoded
PKCS#10 format. This certificate request should be supplied to the CA. Most Certificate Authorities
return Base64 encoded PKCS#7 certificate data that you can import directly into System
Management Homepage by selecting Settings->System Management Homepage.
If the CA returns the certificate data in X.509 format, rename the X.509 certificate file as cert.pem
and place it into the \hp\sslshare directory. When System Management Homepage is restarted,
this certificate is used.
Why is my PKCS#7 data cert data not accepted?
Solution: When using a Mozilla browser, there can be problems when cutting and pasting cert
request and reply data when using Notepad or other editors. To avoid these problems always use
Mozilla to open any certificate reply files from your CA. Be sure to use the Select All, Cut , and
Paste operations that are supplied by Mozilla when working with certificates.
Why is my private key file not protected by the file system?
Solution: If you are using Windows operating systems, you must have the system drive in NTFS
format for the private key file to be protected by the file system.
Why do I get errors when I paste my customer-generated certificate PKCS#7 data
into the HP Systems Insight Manager Certificate Data field in Settings->System
Management Homepage->Security->Trusted Management Servers ?
Solution: The customer-generated certificate PKCS#7 data does not belong in the Trusted
Management Servers field. The PKCS#7 data should be imported into the Customer Generated
Certificates Import PKCS#7 Data field under Settings→System Management
Homepage→Security→Local Server Certificate. The HP Systems Insight Manager Certificate
Data field is used to configure which HP Systems Insight Manager servers are trusted by the System
Management Homepage. For more information, refer to "Trusted Management Servers".
Why can't I use a Windows 2003 Certificate Authority to grant my third-party
certificate into the System Management Homepage?
Solution: To use a Windows 2003 Certificate Authority to create a certificate for System
Management Homepage:
1. Create the PKCS#10 data packet by clicking Settings->System Management
Homepage->Security->Local Server Certificate page.
2. Press the Ctrl+ C keys to copy the data into a buffer.
3. Navigate to http://W2003CA/certsrv where W2003CA is the name of your Windows
2003 Certificate Authority system.
38
Troubleshooting