<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ProCurve Switch 2510G-24 configure connection https and telnet in HPE Aruba Networking &amp; ProVision-based</title>
    <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730369#M7698</link>
    <description>&lt;P&gt;By default, telnet, ssh, and http are enabled on the switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To enable https, you first need to create a certificate. You can create a self-signed certificate or you can request one from a certificate authority. You first need to set the time or better yet use sntp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To setup SNTP:&lt;BR /&gt;&amp;nbsp; timesync sntp&lt;BR /&gt;&amp;nbsp; sntp unicast&lt;BR /&gt;&amp;nbsp; sntp server priority 1 10.1.1.10&lt;BR /&gt;&amp;nbsp; time daylight-time-rule continental-us-and-canada&lt;BR /&gt;&amp;nbsp; time timezone -420&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To create a self-signed certificate:&lt;BR /&gt;&amp;nbsp; crypto key generate cert rsa bits 2048&lt;BR /&gt;&amp;nbsp; crypto host-cert generate self-signed&lt;BR /&gt;&amp;nbsp; (answer the prompts)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To enable https:&lt;BR /&gt;&amp;nbsp; web-management ssl&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To disable http:&lt;BR /&gt;&amp;nbsp; no web-management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To disable telnet:&lt;BR /&gt;&amp;nbsp; no telnet-server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to get a signed certificate, the process is more involved and unless you have a company certificate authority, it will cost money to get it and really isn't necessary. But here is the process. If that is what you want to do, let me know and I will give you the steps. Or you can look at the manuals.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2015 15:59:59 GMT</pubDate>
    <dc:creator>EricAtHP</dc:creator>
    <dc:date>2015-04-08T15:59:59Z</dc:date>
    <item>
      <title>ProCurve Switch 2510G-24 configure connection https and telnet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730328#M7695</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i've a switch HP, i want to change the browsing from http to https&lt;/P&gt;&lt;P&gt;and open the connection instead of telnet the connection:&lt;/P&gt;&lt;P&gt;SSH port 22&lt;/P&gt;&lt;P&gt;I tried to check the configuration but i think for change this parameter is need a command line,&lt;/P&gt;&lt;P&gt;someone can help me&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Santino&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 13:57:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730328#M7695</guid>
      <dc:creator>Santy01</dc:creator>
      <dc:date>2015-04-08T13:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve Switch 2510G-24 configure connection https and telnet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730369#M7698</link>
      <description>&lt;P&gt;By default, telnet, ssh, and http are enabled on the switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To enable https, you first need to create a certificate. You can create a self-signed certificate or you can request one from a certificate authority. You first need to set the time or better yet use sntp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To setup SNTP:&lt;BR /&gt;&amp;nbsp; timesync sntp&lt;BR /&gt;&amp;nbsp; sntp unicast&lt;BR /&gt;&amp;nbsp; sntp server priority 1 10.1.1.10&lt;BR /&gt;&amp;nbsp; time daylight-time-rule continental-us-and-canada&lt;BR /&gt;&amp;nbsp; time timezone -420&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To create a self-signed certificate:&lt;BR /&gt;&amp;nbsp; crypto key generate cert rsa bits 2048&lt;BR /&gt;&amp;nbsp; crypto host-cert generate self-signed&lt;BR /&gt;&amp;nbsp; (answer the prompts)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To enable https:&lt;BR /&gt;&amp;nbsp; web-management ssl&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To disable http:&lt;BR /&gt;&amp;nbsp; no web-management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To disable telnet:&lt;BR /&gt;&amp;nbsp; no telnet-server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to get a signed certificate, the process is more involved and unless you have a company certificate authority, it will cost money to get it and really isn't necessary. But here is the process. If that is what you want to do, let me know and I will give you the steps. Or you can look at the manuals.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 15:59:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730369#M7698</guid>
      <dc:creator>EricAtHP</dc:creator>
      <dc:date>2015-04-08T15:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve Switch 2510G-24 configure connection https and telnet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730673#M7704</link>
      <description>&lt;P&gt;Thk for your support but i've only a problem to To create a self-signed certificate,&lt;/P&gt;&lt;P&gt;the command you posted:&lt;/P&gt;&lt;P&gt;&amp;nbsp; crypto key generate cert rsa bits 2048&lt;/P&gt;&lt;P&gt;&amp;nbsp;is not valid, see below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ProCurve Switch 2510G-24(config)# crypto help&lt;BR /&gt;Usage: crypto host-cert generate self-signed [START END CNAME OU ORG&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CITY STATE COUNTRY]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; crypto host-cert zeroize&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; crypto key generate &amp;lt;ssh [rsa] | cert [rsa] KEYSIZE&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; crypto key zeroize &amp;lt;ssh | cert&amp;gt;&lt;/P&gt;&lt;P&gt;Description: Install or remove authentication files for ssh or https server.&lt;/P&gt;&lt;P&gt;Parameters:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o host-cert - operation on the https host certificate file. The host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; certificate file cannot be created before the certificate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rsa key file has been created.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o key - operation on an ssh or https rsa key file.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o generate - install new key or self-signed certificate.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Note: installing a new key may be very slow in the first few&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; minutes after booting the device.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o zeroize - remove an existing key or certificate file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o self-signed - install new self-signed certificate.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o START - certificate will be valid beginning on this date.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o END - certificate will be valid until this date.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o CNAME - the name (IP address) of this device.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o OU - organizational unit or department.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o ORG - organization name.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o CITY - city or location.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o STATE - state or region.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o COUNTRY - two character ISO country code.&amp;nbsp; Typing 'x&amp;lt;TAB&amp;gt;' will&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; provide a list of all valid country codes beginning with&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the letter x.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o ssh - Install/remove host key for ssh server.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o cert - Install/remove rsa key for https certificate.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o rsa - optional keyword indicating key type (only rsa is available).&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o KEYSIZE - for a certificate key, the size of the key desired.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Certificate keys may be 512, 768, or 1024 bits.&amp;nbsp; (Ssh host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keys are always 896 bits.)&lt;/P&gt;&lt;P&gt;ProCurve Switch 2510G-24(config)#&lt;BR /&gt;ProCurve Switch 2510G-24(config)# crypto key generate cert rsa bits 2048&lt;BR /&gt;Invalid input: bits&lt;BR /&gt;ProCurve Switch 2510G-24(config)# crypto key generate cert rsa keysize 2048&lt;BR /&gt;Invalid input: keysize&lt;BR /&gt;ProCurve Switch 2510G-24(config)#&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 08:57:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730673#M7704</guid>
      <dc:creator>Santy01</dc:creator>
      <dc:date>2015-04-09T08:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve Switch 2510G-24 configure connection https and telnet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730777#M7711</link>
      <description>&lt;P&gt;I generating these commands on a 2920 so there is a chance that they are slightly different. You may also update the software.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any case, use the &amp;lt;tab&amp;gt; key as you type a command to see the options that come next.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something like "&lt;SPAN&gt;crypto key generate cert rsa KEYSIZE" should work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It also may be that the version of software you are running doesn't support&amp;nbsp;a keysize of&amp;nbsp;2048 and only 1024. Use what ever is available.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 14:32:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6730777#M7711</guid>
      <dc:creator>EricAtHP</dc:creator>
      <dc:date>2015-04-09T14:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve Switch 2510G-24 configure connection https and telnet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6732758#M7767</link>
      <description>&lt;P&gt;I upgraded the firmware and i was able to generate the certificate and enable the https trafic,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;i tried to enable also SSH but explain this error message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;ssh cannot be enabled until a host key is configured (use 'crypto' command)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why if i've already used crypto command for create the certificare:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;crypto key generate cert 1024&lt;/P&gt;&lt;P&gt;&amp;nbsp;crypto host-cert generate self-signed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thk in advance for help&lt;/P&gt;&lt;P&gt;Santino&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2015 07:43:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6732758#M7767</guid>
      <dc:creator>Santy01</dc:creator>
      <dc:date>2015-04-15T07:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve Switch 2510G-24 configure connection https and telnet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6732903#M7769</link>
      <description>&lt;P&gt;Interesting, I haven't played with the 2510 but 2920 and higher have SSH enabled by default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can&amp;nbsp;generate a key with a command like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;crypto key generate ssh rsa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;optionally, use the 'bits' option after rsa to specify how big of a key you want.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you are typing these commands use the &amp;lt;tab&amp;gt; key to do auto-complete as well as to see the available options for the next part of the command.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2015 14:25:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/procurve-switch-2510g-24-configure-connection-https-and-telnet/m-p/6732903#M7769</guid>
      <dc:creator>EricAtHP</dc:creator>
      <dc:date>2015-04-15T14:25:16Z</dc:date>
    </item>
  </channel>
</rss>

