Got it

SSL login

Created: Mar 31, 2021 01:59:07Latest reply: Mar 31, 2021 02:03:28 356 1 1 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello,

We need to improve login security for the S5700-28P-LI-4AH. Kindly provide a list of requirements as well as procedures to disable SSLv3 and use TLSv1.2 instead.

We presume the below procedure should be referenced, please assist to clarify if the need for a digital certificate is required to achieve this.

https://support.huawei.com/enterprise/en/doc/EDOC1100038337/bb2bd06d/configuring-an-ssl-policy-and-loading-a-digital-certificate



Featured Answers

Recommended answer

Popeye_Wang
Admin Created Mar 31, 2021 02:03:28

Hi,

You can configure login through the web system in simple mode or secure mode:

If you configure web system login in simple mode:

 · The device provides a default SSL policy, and the web page file contains a randomly generated self-signed certificate. If the default SSL policy and self-signed certificate meet security requirements, you do not need to upload a digital certificate or configure an SSL policy. The configuration of this mode is simple but brings security risks. It applies to scenarios that do not have high-security requirements

· you can configure Device Login Through the Web System (Simple Mode) by following steps here

 

If you configure web system login in secure mode:

· For security purposes, it is recommended that you use secure mode to configure device login through the web system. This mode involves manually configuring an SSL policy and helps ensure security

·  You can configure Device Login Through the Web System (Secure Mode) by following steps Here

·  You need to configure an SSL policy and load a digital certificate

·  To disable SSLV3 to disable SSLv3 and use TLSv1.2 instead run >> ssl minimum version tls1.2

·  This command configures a minimum SSL version for an SSL policy as reference Here

 

Example

# Configure the minimum SSL version for the SSL policy ftp_server to be TLS1.2.


<HUAWEI> system-view

[HUAWEI] ssl policy ftp_server

[HUAWEI-ssl-policy-ftp_server] ssl minimum version tls1.2


View more
  • x
  • convention:

All Answers

Hi,

You can configure login through the web system in simple mode or secure mode:

If you configure web system login in simple mode:

 · The device provides a default SSL policy, and the web page file contains a randomly generated self-signed certificate. If the default SSL policy and self-signed certificate meet security requirements, you do not need to upload a digital certificate or configure an SSL policy. The configuration of this mode is simple but brings security risks. It applies to scenarios that do not have high-security requirements

· you can configure Device Login Through the Web System (Simple Mode) by following steps here

 

If you configure web system login in secure mode:

· For security purposes, it is recommended that you use secure mode to configure device login through the web system. This mode involves manually configuring an SSL policy and helps ensure security

·  You can configure Device Login Through the Web System (Secure Mode) by following steps Here

·  You need to configure an SSL policy and load a digital certificate

·  To disable SSLV3 to disable SSLv3 and use TLSv1.2 instead run >> ssl minimum version tls1.2

·  This command configures a minimum SSL version for an SSL policy as reference Here

 

Example

# Configure the minimum SSL version for the SSL policy ftp_server to be TLS1.2.


<HUAWEI> system-view

[HUAWEI] ssl policy ftp_server

[HUAWEI-ssl-policy-ftp_server] ssl minimum version tls1.2


View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.