<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL communications between VCA and VCRM in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/ssl-communications-between-vca-and-vcrm/m-p/4704329#M42338</link>
    <description>&lt;!--!*#--&gt;My current organization makes little distinction between securing passwords on the intranet and Internet and as a result, we limit SSL ciphers to those that offer high encryption on both internal and external servers.&lt;BR /&gt;  &lt;BR /&gt;In addition to ensuring that Windows was configured to only use high encryption ciphers, I recently made changes to the allowed cipher suites for SMH using smhconfig.exe.  Specifically, I now have the following:&lt;BR /&gt;&lt;BR /&gt;SSLCipherSuite ALL:!ADH:!EXPORT56:!EXPORT40:RC4+RSA:+HIGH:-MEDIUM:-SSLv2:-EXP:-LOW:-eNULL&lt;BR /&gt;&lt;BR /&gt;I have also been working on the certificates to replace the self-signed certificates using the netbios computer name with certificates issued to the FQDN and signed by our local CA.&lt;BR /&gt;  &lt;BR /&gt;I can browse to the SMH on all my servers.  SMH is using the correct certificate and at first everything seems to be in order.  Unfortunately, when I try to connect to the VCRM from the VCA, the VCA is reporting:&lt;BR /&gt;&lt;BR /&gt;The specified repository &lt;SERVER fqdn=""&gt; is invalid or not reachable.&lt;BR /&gt;&lt;BR /&gt;I have tried accessing it from both the VCRM server and other servers and I have also tried the netbios name as well as just the IP address.  The account we use to connect to the VCRM is in the local administrators group, so that is not the issue.  In all cases, I can successfully connect to the VCRM from any server using the URL:  https://&lt;SERVER fqdn=""&gt;:2381/vcrepository.  I have verified that the certificate I get when browsing to the URL is the same certificate in the trusted management servers certificates list.&lt;BR /&gt;  &lt;BR /&gt;So I am wondering, is the VCA is capable of using a high encryption cipher?  &lt;BR /&gt;&lt;/SERVER&gt;&lt;/SERVER&gt;</description>
    <pubDate>Mon, 25 Oct 2010 11:45:35 GMT</pubDate>
    <dc:creator>Rob C.</dc:creator>
    <dc:date>2010-10-25T11:45:35Z</dc:date>
    <item>
      <title>SSL communications between VCA and VCRM</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-communications-between-vca-and-vcrm/m-p/4704329#M42338</link>
      <description>&lt;!--!*#--&gt;My current organization makes little distinction between securing passwords on the intranet and Internet and as a result, we limit SSL ciphers to those that offer high encryption on both internal and external servers.&lt;BR /&gt;  &lt;BR /&gt;In addition to ensuring that Windows was configured to only use high encryption ciphers, I recently made changes to the allowed cipher suites for SMH using smhconfig.exe.  Specifically, I now have the following:&lt;BR /&gt;&lt;BR /&gt;SSLCipherSuite ALL:!ADH:!EXPORT56:!EXPORT40:RC4+RSA:+HIGH:-MEDIUM:-SSLv2:-EXP:-LOW:-eNULL&lt;BR /&gt;&lt;BR /&gt;I have also been working on the certificates to replace the self-signed certificates using the netbios computer name with certificates issued to the FQDN and signed by our local CA.&lt;BR /&gt;  &lt;BR /&gt;I can browse to the SMH on all my servers.  SMH is using the correct certificate and at first everything seems to be in order.  Unfortunately, when I try to connect to the VCRM from the VCA, the VCA is reporting:&lt;BR /&gt;&lt;BR /&gt;The specified repository &lt;SERVER fqdn=""&gt; is invalid or not reachable.&lt;BR /&gt;&lt;BR /&gt;I have tried accessing it from both the VCRM server and other servers and I have also tried the netbios name as well as just the IP address.  The account we use to connect to the VCRM is in the local administrators group, so that is not the issue.  In all cases, I can successfully connect to the VCRM from any server using the URL:  https://&lt;SERVER fqdn=""&gt;:2381/vcrepository.  I have verified that the certificate I get when browsing to the URL is the same certificate in the trusted management servers certificates list.&lt;BR /&gt;  &lt;BR /&gt;So I am wondering, is the VCA is capable of using a high encryption cipher?  &lt;BR /&gt;&lt;/SERVER&gt;&lt;/SERVER&gt;</description>
      <pubDate>Mon, 25 Oct 2010 11:45:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-communications-between-vca-and-vcrm/m-p/4704329#M42338</guid>
      <dc:creator>Rob C.</dc:creator>
      <dc:date>2010-10-25T11:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSL communications between VCA and VCRM</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-communications-between-vca-and-vcrm/m-p/4704330#M42339</link>
      <description>Are you able to open all other available webapps in SMH, on your setup ?&lt;BR /&gt;&lt;BR /&gt;Thanks.</description>
      <pubDate>Thu, 28 Oct 2010 07:03:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-communications-between-vca-and-vcrm/m-p/4704330#M42339</guid>
      <dc:creator>pkrai</dc:creator>
      <dc:date>2010-10-28T07:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL communications between VCA and VCRM</title>
      <link>https://community.hpe.com/t5/server-management-systems/ssl-communications-between-vca-and-vcrm/m-p/4704331#M42340</link>
      <description>pkrai - Yes. You also responded to a related posting on this:  &lt;A href="http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1452725&amp;amp;admit=109447626+1288266351048+28353475." target="_blank"&gt;http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1452725&amp;amp;admit=109447626+1288266351048+28353475.&lt;/A&gt;  Based on what I have been doing with the certificates, I am starting to think that I broke it.  I am not sure that I'll be able to manage certificates for HP management software the way I want...</description>
      <pubDate>Thu, 28 Oct 2010 10:54:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/ssl-communications-between-vca-and-vcrm/m-p/4704331#M42340</guid>
      <dc:creator>Rob C.</dc:creator>
      <dc:date>2010-10-28T10:54:05Z</dc:date>
    </item>
  </channel>
</rss>

