Brocade Fabric OS Command Reference Guide v6.1.0 (53-1000599-02, June 2008)

Table Of Contents
Fabric OS Command Reference 41
53-1000599-02
authUtil
2
Sets the hash type. Valid values are “sha1”, “md5” or “all”, which sets both
hash types. Use this option to disable md5 authentication access by setting
the hash type to sha1 only. Disabling md5 access is required when
configuring the system for FIPS. Refer to the Fabric OS Administrator’s Guide
for details on FIPS configuration.
--policy Sets the switch authentication policy or device authentication policy. The
following options are supported:
-sw on|off|active|passive
Sets the switch authentication policy. Specify one of the following modes.
Operands are exclusive.
on Sets the switch authentication policy to ON mode. Strict authentication is
enforced on all E_Ports. The inter-switch link (ISL) goes down (port disable), if
the connecting switch does not support the authentication or the
authentication policy is switched off.
off Turns the authentication policy off, and the switch rejects any authentication
requests.
active Sets the authentication policy to active mode. During switch initialization,
authentication is initiated on all E_Ports, but the port is not disabled if the
connecting switch does not support authentication or the authentication
policy is turned off.
passive (default)
Sets the authentication policy to passive mode. The switch does not initiate
authentication but participates in authentication if the connecting switch
initiates authentication.
-dev off|passive
Sets the device authentication policy. Two modes are supported. Device
authentication policy is off by default.
off Turns off the device authentication policy. Authentication is not required. The
switch ignores any authentication requests and continues with the FC probing
without authentication.
passive Sets the authentication policy to passive mode. Authentication is optional. If
the attached device is capable of doing the authentication then the switch
participates in authentication; otherwise it forms an F_Port without
authentication. In this mode the device accepts authentication on all F_Ports.
authinit [slotnumber/]portnumber [, [slotnumber]/portnumber...| allE
Re-initiates authentication on selected ports after changing the DH-CHAP
group, hash type, and shared secret between a pair of switches. This
command does not work on Private, Loop, NPIV and FICON devices. The
command can re-initiate authentication only if the device was previously
authenticated. This command may bring down the E_Ports if the DH-CHAP
shared secrets are not installed correctly. Valid options include:
slotnumber Specify the slot number, if applicable, followed by a slash (/).
portnumber Specify the port number. On enterprise-class platforms, use the
slotnumber/portnumber format for specifying the port number.