You are on page 1of 13

ESRS HTTPS Listener Service

SSL

300-013-818 A01
2012 7

.............................................................................................................. 2
.............................................................................................................. 2
HTTPS ................................................................................................. 3
X.509 ............................................................................... 4
ESRS HTTPS Listener Service X.509 ......... 7
ConnectHome ................................................. 11
.................................................................................................... 12

ConnectHome
Microsoft Windows EMC Secure Remote
Support (ESRS) HTTPS Listener Service HTTPS

HTTPS ESRS HTTPS Listener Service


X.509 ConnectHome

ESRS HTTPS Listener (EHL) Service


ESRS IP EMC ConnectEMC
HTTPS
HTTPS
HTTP Secure HTTP over SSL
X.509 SSL

PKI

X.509

ESRS Listener Service SSL

HTTPS

HTTPS
HTTPS HTTP

HTTPS

X.509

HTTPS

HTTPS

ConnectHome

(CA) X.509
CA

X.509

IP
IP

EHL

ESRS Listener Service SSL

X.509

X.509
X.509

(CA) EHL ConnectHome


EHL
(CSR) EHL

ConnectHome

EHL X.509

1.

EHL Windows Microsoft


(MMC) mmc

2.

Windows

ESRS Listener Service SSL

X.509

3.

4.

()

IP

ConnectHome

X.509
X.509

1.

EHL IP
ConnectHome ID IP
IP Address: 10.245.52.25

2.

SSH root

ESRS Listener Service SSL

X.509

3.

X.509

openssl req x509 newkey rsa:1024 out mycert.pem keyout


mykey.pem days 365 outform PEM

mycert.pem mykey.pem 1024


-newkey rsa:2048
-days
(mykey.pem)
HTTPS

4.

(mycert.pem)
(mykey.pem) PKCS #12 EHL
Windows
Openssl pkcs12 export out mypkg.p12 in mycert.pem inkey
mykey.pem

5.

PKCS #12 (mypkg.p12) EHL


Windows
mykey.pem
mycert.pem

ESRS Listener Service SSL

ESRS HTTPS Listener Service X.509

ESRS HTTPS Listener Service X.509


ESRS HTTPS Listener Service

1.

X.509

2.

EHL

X.509
PKCS #12 EHL
X.509
1.

Microsoft (MMC)

2.

3.
4.

()

PKCS#12

ESRS Listener Service SSL

ESRS HTTPS Listener Service X.509

5.

::

PKCS#12
3
()

ESRS Listener Service SSL

ESRS HTTPS Listener Service X.509

EHL
EHL
EHL X.509
1.

2.

SHA 1

ESRS Listener Service SSL

ESRS HTTPS Listener Service X.509

3.

4.

Windows esrshttps.exe
C:\Program Files\EMC\ESRS IP
Client\Gateway\ESRSHTTPS

5.

esrshttps.exe config

6.

10

= https
IP = EHL IP X.509

= 443

ESRS Listener Service SSL

ConnectHome

ESRS IP

C:\Program Files\EMC\ESRS IP Client


SSLHASH = 3 SHA 1

o
o

DACEB92817329422A3C8A7421874EF1E8AFF67A3
NOT da ce b9 28 17 32 94 22 a3 c8 a7 42 18 74 ef 1e 8a ff 67
a3

7.

8.

esrshttps.exe.config

9.

EHL

10.
SSLHash

ConnectHome
ConnectHome EHL
EHL
CA
CA PEM

ConnectHome :
nas_connecthome modify https_ca_file
/path/to/cert/mycert.pem

ESRS Listener Service SSL

11

EHL
nas_connecthome https_verify_server yes

nas_connecthome test https

ConnectHome EHL HTTPS

12

EHL X.509
o

IP EHL
IP

ConnectHome
IP
X.509

esrshttps.exe.config

EHL esrshttps.log
HTTPS (443)

EMC
http://Support.EMC.comEMC Secure Remote
Support IP Solutions GuideEMC IP

X.509
ConnectHome

ESRS Listener Service SSL

2012 EMC Corporation


EMC
EMC CORPORATION

EMC
EMC www.EMC2.com.cn EMC Corporation

ESRS Listener Service SSL

13

You might also like