12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 5: Elementary CryptographyThe next step is to establish the identity of the user of the digital certificate,which is accomplished by the registration authority (RA). The RAdoes not issue certificates but acts as an intermediary between theuser and the CA. The role of the CA may be carried out by an actualhuman or by software running on a CA device.What happens when a digital certificate expires or is revoked becauseit has been compromised? In that case, a certificate revocation list(CRL) is maintained at the CA and consulted each time a transactiontakes place using a digital certificate.Where <strong>Brocade</strong> is the CA, a PKI is used to distribute <strong>Brocade</strong> digitalcertificates.InternetCA issuescertificateUser requestscertificate from RACARA validesuser’s identityand informs CARACRL is checked forrevoked certificatesCRLCertificate:JhiGhr*7km893%re84_)Kflg@Di*fi$3Lkvl#?kdfM_c&ll$mvoMk!. . .Figure 6. Public key infrastructureSSLSecure Socket Layer (SSL) was developed out of a need to encryptcommunications over the Internet and addresses only the confidentialityof data-in-flight. It was originally developed by Netscape in 1994and SSLv3.0 is the most widely used today.It is a hybrid encryption system using both symmetric and asymmetriccryptography. Public key cryptography is used to authenticate betweenclients and servers, whereas symmetric cryptography is used toencrypt the application data. The application data can be encryptedusing a 40-bit or 128-bit symmetric key version. The authentication isperformed using digital certificates obtained from a CA in a PKIframework.86 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!