
Diagnostic com
mands
host run – look up the host specified using the domain server.
Syntax
hostname (config)# host run <hostname>
Related
command(s)
•tracerouterun
•netstatrun
•pingrun
ping run – send ICMP ECHO_REQUEST packets to the specified network host.
Syntax
hostname (config)# ping run <hostname>
Related
command(s)
•hostrun
•tracerouterun
•netstatrun
netstat ru
n – generate a list of all active connections on the SKM.
Syntax
hostname (config)# netstat run
Related
command(s)
•hostrun
•tracerouterun
•pingrun
traceroute run –printtheroutepacketstaketothespecified network host.
Syntax
hostname (config)# traceroute run <hostname>
Related
command(s)
•hostrun
•netstatrun
•pingrun
FIPS commands
fips
compliant – make the device FIPS-compliant.
This
will alter various server settings, as documented in Using advanced security features.
IMPORTANT:
According to FIPS requirements, you cannot enable or disable FIPS when there are keys on the SKM.
You must
manually
delete all keys before enabling and disabling FIPS compliance. Keys are zeroized
upon deletion.
We strongly recommend that you back up your keys before deleting.
IMPORTANT:
Setting this device to be FIPS-compliant forces SSL connections to the KMS Server and to the Web
Adm
inistration service to use TLS 1.0 only. Some Web browsers, including Internet Explorer 6.0, do
not
have TLS 1.0 enabled by default. If your browser is no longer able to make a connection to this
dev
ice,pleasecheckthatithasTLS1.0enabled.(InInternetExplorer,selectInternetOptionsfromthe
Tools menu, click the Advanced tab, scroll down to the Security section, and make sure the “Use TLS
1. 0 ” c h e c k b o x i s c h e c k e d . )
Syntax
hostname# fips compliant
This device is now FIPS-compliant.
Related
command(s)
•sh
ow fips status
fips server – enable the FIPS status server and assign it an IP and a port.
Secure Key Manager
269
Commentaires sur ces manuels