Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

Dell Unity™ Family Unisphere® Command Line Interface User Guide

Change security settings

Change the system security settings.

Format

/sys/security set {-fips140Enabled {yes | no} | -tlsMode {TLSv1.0 | TLSv1.1 | TLSv1.2} | -restrictedShellEnabled {yes | no}}

Action qualifiers

QualifierDescription
-fips140EnabledEnables or disables FIPS 140 compliance mode. Valid values are:
  • yes
  • no
-tlsMode Specify the lowest version of the TLS protocol the system supports for SSL communication. Valid values are:
  • TLSv1.0
  • TLSv1.1
  • TLSv1.2
NOTE: Specifying TLS 1.1 or TLS 1.2 may impact existing client applications which are not compatible with the respective TLS protocols. The following functionality will not work when TLS 1.1 is specified:
  • Replication from or to OE versions earlier than 4.3 are not supported.
  • For Unisphere, if a browser is restricted to use TLS 1.0 and the tlsMode is set to support either TLS 1.1 or TLS 1.2 on the system, the Unisphere login page will not load and a security failure will appear.
The following functionality will not work when TLS 1.2 is specified:
  • Replication from or to OE versions earlier than 4.3 are not supported.
  • For Unisphere, if a browser is restricted to use TLS 1.1 and the tlsMode is set to TLS 1.2 on the system, the Unisphere login page will not load and a security failure will appear.
  • All existing Unisphere CLI client releases (that is, Unisphere CLI client version 5.0.2 and earlier) do not support TLS 1.2. If you are using Unisphere CLI clients and disable TLS 1.1, the Unisphere CLI clients will not be able to connect with Unity. In this case, you must install Unisphere CLI client version 5.0.3 to connect with Unity.
-restrictedShellEnabled Enables or disables restricted shell on the storage processor for the Service account. Valid values are:
  • yes
  • no

Examples

The following command changes the system security setting for FIPS 140 mode:

uemcli -d 10.0.0.1 -u Local/joe -p MyPassword456! /sys/security set -fips140Enabled yes
Storage system address: 10.0.0.1
Storage system port: 443
HTTPS connection
The system will reboot one SP at a time for this change to take effect. Do you want to continue?
yes / no: yes

Operation completed successfully.

The following command changes the system security setting for the TLS mode:

uemcli -d 10.0.0.1 -u Local/joe -p MyPassword456! /sys/security set -tlsMode TLSv1.1
Storage system address: 10.0.0.1
Storage system port: 443
HTTPS connection
Please refer to the Security Configuration Guide for backward compatibility. 
This change may impact running operations (e.g. replication) and the management services will be automatically restarted for the change to take effect. 
Do you want to continue?
yes / no: yes

Operation completed successfully.
NOTE:The security set -tlsMode command does not update the supported TLS protocol versions for a NAS server. Use the svc_nas service script to configure the supported TLS protocol versions for a NAS server. For more information about this service script, refer to the Dell Unity Family Service Commands Technical Notes.

The following command changes the system security setting for restricted shell enabled setting:

uemcli -d 10.0.0.1 -u Local/joe -p MyPassword456! /sys/security set -restrictedShellEnabled no
Storage system address: 10.0.0.1
Storage system port: 443
HTTPS connection
This action will disable restricted shell for service account on the storage processor. Do you want to continue?
yes / no: yes

Operation completed successfully.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\