
10 Manage security
Primarily, securing CloudSystem appliances require attention to properly managing certificates.
This chapter and Security in CloudSystem (page 22) provide guidance on using certificates in
CloudSystem. See also Troubleshooting security settings (page 149).
Note that this software provides the ability to enable or disable service access. To learn more
about this feature, see Enabling or disabling authorized services access (page 24)
Access to the appliance console
Use the hypervisor management software to restrict access to the appliance, which prevents
unauthorized users from accessing the password reset and service access features. See Restricting
console access (page 24).
Typical legitimate uses for access to the console are:
• Troubleshooting network configuration issues.
• Resetting an appliance administrator password.
For information on how to reset the administrator password, see the online help.
• Enabling service access by an on-site authorized support representative.
The virtual appliance console is displayed in a graphical console; password reset and HP Services
access use a non-graphical console.
Procedure 23 Switching from one console to another (VMware vSphere)
1. Open the virtual appliance console.
2. Press and hold Ctrl+Alt.
3. Press and release the space bar.
4. Press and release F1 to select the non-graphical console or F2 to select the graphical console.
Procedure 24 Switching from one console to another (KVM)
1. Open the Virtual Machine Manager.
2. In the Menu bar, select Send Key→Ctrl+Alt+F1 for the non-graphical console or select Send
Key→Ctrl+Alt+F2 for the graphical console.
Downloading and importing a self-signed certificate
The advantage of downloading and importing a self-signed certificate is to circumvent the browser
warning.
In a secure environment, it is never appropriate to download and import a self-signed certificate,
unless you have validated the certificate and know and trust the specific appliance.
In a lower security environment, it might be acceptable to download and import the appliance
certificate if you know and trust the certificate originator. However, HP does not recommend this
practice.
Microsoft Internet Explorer and Google Chrome share a common certificate store. A certificate
downloaded with Internet Explorer can be imported with Google Chrome as well as Internet
Explorer. Likewise, a certificate downloaded with Google Chrome can also be imported by both
browsers. Mozilla Firefox has its own certificate store, and must be downloaded and imported
with that browser only.
The procedures for downloading and importing a self-signed certificate differ with each browser.
Procedure 25 Downloading a self-signed certificate with Microsoft Internet Explorer 9
1. Click in the Certificate error area.
2. Click View certificate.
Access to the appliance console 67
Comentários a estes Manuais