HP System Management Homepage 7.0 Installation Guide

2. Click Add File to browse and select any certificates to be included in the Trusted
Certificate List. The Add File dialog box appears. If you entered an invalid file name
in the file name field, an error message appears indicating the file does not exist.
Click OK to select another file, or click Cancel to close the dialog box. The Trusted
Certificate List appears.
Note: If you click Next without adding any certificates to the list and no certificates
exist from a previous installation, a message appears indicating that if you do not
specify any trusted certificates, HP SIM cannot access the HP Web-based Agents on
this system. Click OK if you do not want HP SIM to access the HP Web-based Agents
on this system, or click Cancel to close the dialog box and add the trusted certificates
to the list.
Note: The Trust By Certificate option enables the HP SMH system and the HP SIM
system to establish a trust relationship using certificates. This mode is the strongest
method of security because it requires certificate data and verifies the digital signature
before enabling access.
3. Click Next. The IP Binding dialog box appears.
To import a certificate:
1. Click Import. The Import Server Certificate dialog box appears.
2. Enter the name or IP address of the server whose certificate you want to import.
3. Click Get Cert. The certificate information appears.
4. Verify the certificate information. If you want to add this certificate to the Trusted
Certificate List, click Accept and the certificate is added to the Trusted Certificate List,
or click Cancel if you do not want to add it to the Trusted Certificate List. The Trusted
Certificate List appears.
Note: You can add up to 128 trusted certificates.
5. Click Next. The IP Binding dialog box appears.
Note: To delete a certificate, select the certificate and click Delete.
Trust By Name
1. Select Trust By Name.
2. Click Next. The Trusted Server dialog box appears.
Note: Although the Trust By Name mode is a slightly better security method than the
Trust All mode, your system is still vulnerable to security attacks. The Trust By Name
mode sets up HP SMH to accept only certain requests from servers with the HP SIM
certificate names designated in the Trust By Name field. The Trust By Name option
is easy to configure and can prevent unauthorized access. For example, you might
want to use the Trust By Name option if you have a secure network, but your network
has two groups of administrators in two separate divisions. The Trust By Name option
would prevent one group from installing software on the wrong system. This option
does not verify anything other than the HP SIM certificate name submitted.
22 Installing HP SMH on a Windows operating system