HP Systems Insight Manager User Manual

Page 66

Advertising
background image

selected, any local user has access limited to unsecured pages without being
challenged for a user name and password.

Caution: HP does not recommend the use of local access unless your management
server software enables it.

g.

Click Next. You can click Save to save your changes up to this point, or click Cancel
to discard the changes and close the wizard.

h.

Select one of the following Trust Mode security options:

Trust by Certificate

Sets the

System Management Homepage

(SMH) to accept

configuration changes only from HP SIM servers with trusted certificates. This mode
requires the submitted server to provide authentication by means of certificates.
This mode is the strongest method of security because it requires certificate data
and verifies the digital signature before allowing access. If you do not want to
enable any remote configuration changes, leave Trust by Certificate selected,
and leave the list of trusted systems empty by avoiding importing any certificates.

NOTE:

HP strongly recommends using this option because it is more secure.

To trust by certificate:

1.

Select Trust by Certificate, and click Next.

2.

In the Certificate Name field, click Browse to select the certificate file. After
the certificate file is selected, the certificate data appears on the screen.

3.

Click Add. The certificate appears under Certificate Files. You can click
Save

to save your changes up to this point or click Cancel to discard the

changes and close the wizard.

4.

Click Next. The IP Binding page appears.

Trust by Name

Sets the System Management Homepage to accept certain

configuration changes only from servers with the HP SIM names designated in the
Trust By Name

field. The Trust By Name option is easy to configure. For example,

you might use the Trust By Name option if you have a secure network with two
separate groups of administrators in two separate divisions. It prevents one group
from installing software to the wrong system. This option verifies only the HP SIM
server name submitted.

NOTE:

HP strongly recommends using the Trust by Certificate option because

the other options are less secure.

The server name option must meet the following criteria:

Each server name must be less than 64 characters.

The overall length of the server name list is 1,024 characters.

Special characters should not be included as part of the server name: ~ '
! @ # $ % ^ & * ( ) + = \ ": ' < > ? , | .

Semicolons are used to separate server names.

To trust by name:

1.

Select Trust by Name, and click Next.

2.

In the Trusted Server Name field, enter the server name to be trusted.

3.

Click Add. The trusted system name appears under the Trusted Servers list.
You can click Save to save your changes up to this point or click Cancel to
discard the changes and close the wizard.

4.

Click Next. The IP Binding page appears.

Trust All

Sets the System Management Homepage to accept certain configuration

changes from any system.

66

Getting started

Advertising