Manuale d’uso / di manutenzione del prodotto 4000 del fabbricante Sun Microsystems
Vai alla pagina of 204
Sun Microsystems, Inc. 4150 Network Circle Santa Clara, CA 95054 U .S.A. 650-960-1300 Send comments about this document to: docfeedback@sun.com Sun™ Cr ypto Accelerator 4000 Board Installation and User’ s Guide P ar t No .
Please Recycle Copyright 2003 Sun Microsystems, Inc., 4150 Network Cir cle, Santa Clara, CA 95054 U.S.A. All rights reserved. This product or document is distributed under licenses r estricting its use, copying, distribution, and decompilation.
iii Declaration of Conformity (Fiber MMF) EMC European Union This equipment complies with the following r equirements of the EMC Directive 89/336/EEC: As T elecommunication Network Equipment (TNE) in .
iv Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Supplementary Information This product was tested and complies with all the r equirements for the CE Mark.
v As information T echnology Equipment (ITE) Class B per (as applicable): Safety This equipment complies with the following r equirements of the Low V oltage Directive 73/23/EEC: Supplementary Information This product was tested and complies with all the r equirements for the CE Mark.
vi Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003.
vii Regulatory Compliance Statements Y our Sun product is marked to indicate its compliance class: • Federal Communications Commission (FCC) — USA • Industry Canada Equipment Standard for Digita.
viii Sun Crypto Accelerator 4000 Board Installation and User’s Guide • Ma y 2003 ICES-003 Class A Notice - A vis NMB-003, Classe A This Class A digital apparatus complies with Canadian ICES-003. Cet appareil numérique de la classe A est conforme à la norme NMB-003 du Canada.
ix BSMI Class A Notice The following statement is applicable to products shipped to T aiwan and marked as Class A on the product compliance label..
x Sun Crypto Accelerator 4000 Board Installation and User’s Guide • Ma y 2003.
xi Contents 1. Product Overview 1 Product Features 1 Key Protocols and Interfaces 1 Key Features 2 Supported Applications 2 Supported Cryptographic Protocols 2 Diagnostic Support 3 Cryptographic Algor.
xii Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Required Patches 10 Apache W eb Server Patch 10 Solaris 8 Patches 1 1 Solaris 9 Patches 1 1 2.
Contents xiii Noninteractive and Interactive Modes 34 Setting Autonegotiation or Forced Mode 36 ▼ T o Disable Autonegotiation Mode 37 Setting Parameters Using the vca.conf File 38 ▼ T o Set Driver Parameters Using a vca.conf File 38 Setting Parameters for All Sun Crypto Accelerator 4000 vca Devices W ith the vca.
xiv Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Logging In to a New Board 59 Logging In to a Board W ith a Changed Remote Access Key 60 vcaadm Prompt 61 Logging Out .
Contents xv Displaying Board Status 77 Loading New Firmware 78 Resetting a Sun Crypto Accelerator 4000 Board 78 Rekeying a Sun Crypto Accelerator 4000 Board 79 Zeroizing a Sun Crypto Accelerator 4000 Boar d 80 Using the vcaadm diagnostics Command 80 Using vcadiag 81 5.
xvi Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Installing and Configuring Sun ONE Web Server 6.0 101 Installing Sun ONE W eb Server 6.
Contents xvii ▼ Performing the Ethernet FCode Self-T est Diagnostic 129 Troubleshooting the Sun Crypto Accelerator 4000 Board 132 show-devs 132 .properties 133 watch-net 134 A.
xviii Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 E. Manual Pages 161 F . Zeroizing the Hardware 163 Zeroizing the Sun Crypto Accelerator 4000 Hardware to the Factory State 163 ▼ T o Zeroize the Sun Crypto Accelerator 4000 Boar d W ith the Hardwar e Jumper 164 G.
xix T ables TABLE 1-1 IPsec Cryptographic Algorithms 3 TABLE 1-2 SSL Cryptographic Algorithms 3 TABLE 1-3 Supported SSL Algorithms 4 TABLE 1-4 Front Panel Display LEDs for the MMF Adapter 6 TABLE 1-5 .
xx Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 TABLE 3-12 Cryptographic Driver Statistics 43 TABLE 3-13 Ethernet Driver Statistics 44 TABLE 3-14 TX and RX MAC Counte.
Tables xxi TABLE A-9 Performance Specifications 140 TABLE A-10 Power Requirements 140 TABLE A-11 Interface Specifications 141 TABLE A-12 Environmental Specifications 141 TABLE B-1 SSL Protocols 144 TA.
xxii Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003.
xxiii Pr eface The Sun Crypto Accelerator 4000 Board Installation and User ’ s Guide lists the features, protocols, and interfaces of the Sun™ Crypto Accelerator 4000 boar d and describes how to install, configur e, and manage the board in your system.
xxiv Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 ■ Chapter 7 describes how to test the Sun Crypto Accelerator 4000 board with the SunVTS diagnostic application and the onboard FCode self-test. This chapter also provides tr oubleshooting techniques with OpenBoot PROM commands.
Preface xxv T ypographic Conventions Shell Pr ompts T ypeface Meaning Examples AaBbCc123 The names of commands, files, and directories; on-scr een computer output Edit your .
xxvi Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Accessing Sun Documentation Online Y ou can view , print, or purchase a br oad selection of Sun documentation, including localized versions, at: http://www.
1 CHAPTER 1 Pr oduct Overview This chapter provides an overview of the Sun Crypto Accelerator 4000 board, and contains the following sections: ■ “Product Features” on page 1 ■ “Hardwar e Ove.
2 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Key Featur es ■ Gigabit Ethernet with either copper or fiber interface ■ Accelerates IPsec and SSL cryptographic fu.
Chapter 1 Product Overview 3 Diagnostic Support ■ User-executable self-test using OpenBoot™ PROM ■ SunVTS™ diagnostic tests Cryptographic Algorithm Acceleration The Sun Crypto Accelerator 4000 boar d accelerates cryptographic algorithms in both hardwar e and software.
4 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 SSL Acceleration T ABLE 1-3 shows which SSL accelerated algorithms may be off-loaded to hardwar e and which software algorithms are pr ovided for Sun ONE and Apache W eb Servers.
Chapter 1 Product Overview 5 Har dwar e Overview The Sun Crypto Accelerator 4000 hardwar e is a full size (4.2 inches x 12.283 inches) cryptographic accelerator PCI Gigabit Ethernet adapter that enhances the performance of IPsec and SSL on Sun servers.
6 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Sun Crypto Accelerator 4000 MMF Adapter The Sun Crypto Accelerator 4000 MMF adapter is a single-port Gigabit Ethernet fiber optics PCI bus car d. It operates in 1000 Mbps Ethernet networks only .
Chapter 1 Product Overview 7 Sun Crypto Accelerator 4000 UTP Adapter The Sun Crypto Accelerator 4000 UTP adapter is a single-port Gigabit Ethernet copper-based PCI bus car d.
8 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 LED Displays See T ABLE 1-5 . Note – The service pack numbers (SP9 or SP1) are implied whenever Sun ONE W eb Server 4.
Chapter 1 Product Overview 9 Dynamic Reconf iguration and High A vailability The Sun Crypto Accelerator 4000 hardwar e and associated software provides the capability to work effectively on Sun platforms supporting Dynamic Reconfiguration (DR) and hot-plugging.
10 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Har dwar e and Software Requir ements T ABLE 1-6 provides a summary of the har dware and software r equirements for the Sun Crypto Accelerator 4000 adapter .
Chapter 1 Product Overview 11 Solaris 8 Patches The following tables list required and r ecommended Solaris 8 patches to use with this product. T ABLE 1-7 lists and describes required patches. Solaris 9 Patches There ar e currently no requir ed Solaris 9 patches.
12 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003.
13 CHAPTER 2 Installing the Sun Crypto Accelerator 4000 Boar d This chapter describes how to install the Sun Crypto Accelerator 4000 hardware and software.
14 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Installing the Boar d Installing the Sun Crypto Accelerator 4000 board involves inserting the board into the system and loading the software tools. The hardwar e installation instructions include only general steps for installing the board.
Chapter 2 Installing the Sun Cr ypto Accelerator 4000 Board 15 T o determine whether the Sun Crypto Accelerator 4000 device properties ar e listed correctly: fr om the ok prompt, navigate to the device path and type .properties to display the list of properties.
16 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Installing the Sun Crypto Accelerator 4000 Softwar e The Sun Crypto Accelerator 4000 software is included on the Sun Crypto Accelerator 4000 CD. Y ou may need to download patches from the SunSolve web site.
Chapter 2 Installing the Sun Cr ypto Accelerator 4000 Board 17 Y ou see the following files and dir ectories in the /cdrom/cdrom0 directory . The requir ed packages must be installed in a specific order and must be installed before installing any optional packages.
18 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 2. Install the required software packages by typing: 3. (Optional) T o verify that the software is installed properly , run the pkginfo command. 4. (Optional) T o ensure that the driver is attached, you can run the prtdiag command.
Chapter 2 Installing the Sun Cr ypto Accelerator 4000 Board 19 T o install all of the optional software packages, type the following: Refer to T ABLE 2-1 for a description of the package contents of the optional packages in the previous examples.
20 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 FIGURE 2-1 Sun Crypto Accelerator 4000 Dir ectories and Files Note – Once you have installed the hardware and softwar e of the board, you need to initialize the board with conf iguration and keystore information.
Chapter 2 Installing the Sun Cr ypto Accelerator 4000 Board 21 Removing the Softwar e If you have created keystores (r efer to “Managing Keystores W ith vcaadm” on page 69), you must delete the keystore information that the Sun Crypto Accelerator 4000 board is conf igured with before r emoving the software.
22 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Note – After installing or removing the SunVTS test ( SUNWvcav ) for the Sun Crypto Accelerator 4000 board, if SunVTS is already r unning it might be necessary to repr obe the system to update the available tests.
23 CHAPTER 3 Conf iguring Driver Parameters This chapter describes how to configure the vca device driver parameters used by both the Sun Crypto Accelerator 4000 UTP and MMF Ethernet adapters.
24 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 with the remote end of the link (link partner) to select a common mode of operation for the speed , duplex , and link-clock parameters. The link-clock parameter is applicable only if the board is operating at a 1000 Mbps.
Chapter 3 Configuring Dr iver P arameters 25 Advertised Link Parameters The following parameters determine the transmit and receive speed and duplex link parameters to be advertised by the vca driver to its link partner . T ABLE 3-2 describes the operational mode parameters and their default values.
26 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 The Sun Crypto Accelerator 4000 UTP adapter advertised link parameters are differ ent from those of the Sun Crypto Accelerator 4000 MMF adapter as shown in T ABLE 3-2 .
Chapter 3 Configuring Dr iver P arameters 27 If all of the previous parameters ar e set to 1, autonegotiation will use the highest speed possible. If all of the previous parameters are set to 0, you w.
28 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Gigabit For ced Mode Parameter For Gigabit links, this parameter determines the link-master . Generally , switches are enabled as a link master; in which case, this parameter can remain unchanged.
Chapter 3 Configuring Dr iver P arameters 29 have enable-ipg0 enabled might not have enough time on the network. Y ou can add the additional delay by setting the ipg0 parameter from 0 to 255, which is the media byte time delay . T ABLE 3-5 defines the enable-ipg0 and ipg0 parameters.
30 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Interrupt Parameters T ABLE 3-7 describes the receive interrupt blanking values. Random Early Dr op Parameters These parameters provide the ability to drop packets based on the fullness of the receive FIFO.
Chapter 3 Configuring Dr iver P arameters 31 red-dv6to8k 0 to 255 Random early detection and packet drop vectors for when FIFO threshold is gr eater than 6,144 bytes and less than 8,192 bytes. Probability of dr op can be programmed on a 12.5 per cent granularity .
32 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 PCI Bus Interface Parameters These parameters allow you to modify PCI interface features to gain better PCI interperformance for a given application.
Chapter 3 Configuring Dr iver P arameters 33 Setting vca Driver Parameters Y ou can set the vca device driver parameters in two ways: ■ Using the ndd utility ■ Using the vca.conf file If you use the ndd utility , the parameters are valid only until you reboot the system.
34 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Note – In the examples in this user ’s guide, N represents the instance number of the device.
Chapter 3 Configuring Dr iver P arameters 35 Using the ndd Utility in Interactive Mode ● T o modify a parameter value in interactive mode, specify ndd /dev/vca ,a s shown below .
36 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 ● T o list all the parameters supported by the vca driver , type ndd /dev/vca .
Chapter 3 Configuring Dr iver P arameters 37 By default, autonegotiation mode is enabled for these link parameters. When either of these parameters are in autonegotiation mode, the vca device communicates with the link partner to negotiate a compatible value and flow control capability .
38 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Setting Parameters Using the vca.conf File Y ou can also specify the driver parameter properties by adding entries to the vca.
Chapter 3 Configuring Dr iver P arameters 39 The device path name in the first line of the pr evious example is ”/pci@8,600000/network@1” . Device path names are made up of three parts: device parent name, device node name, and device unit address.
40 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 ▼ T o Set Parameters for All Sun Crypto Accelerator 4000 vca Devices W ith the vca.conf File 1. Add a line in the vca.conf f ile to change the value of a parameter for all instances by entering parameter = value ; .
Chapter 3 Configuring Dr iver P arameters 41 Enabling Autonegotiation or For ced Mode for Link Parameters W ith the OpenBoot PROM The following parameters can be configured to operate in autonegotiati.
42 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 When the local link is operating in autonegotiation mode for the speed and duplex parameters at 100 Mbps and below and both full and half duplexes, then the link partner uses either the 100 Mbps or 10 Mbps speeds with either duplex.
Chapter 3 Configuring Dr iver P arameters 43 T o establish a forced mode for a speed of 10 Mbps and an autonegotiation mode for duplex, type the following at the OBP prompt: Y ou could also type the following at the OBP prompt to establish the same local link parameters as the previous example: Refer to the IEEE 802.
44 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Ethernet Driver Statistics T ABLE 3-13 describes the Ethernet driver statistics. T ABLE 3-13 Ethernet Driver Statistics Parameter Description Stable or Unstable ipackets Number of inbound packets.
Chapter 3 Configuring Dr iver P arameters 45 T ABLE 3-14 describes the transmit and receive MAC counters. T ABLE 3-14 TX and RX MAC Counters Parameter Description Stable or Unstable tx-collisions 16-bit loadable counter increments for every frame transmission attempt that resulted in a collision.
46 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 tx-underrun 16-bit loadable counter increments after a valid frame has been received fr om the network.
Chapter 3 Configuring Dr iver P arameters 47 The following Ethernet properties ( T ABLE 3-15 ) ar e derived from the intersection of device capabilities and the link partner capabilities. T ABLE 3-15 describes the current Ethernet link pr operties. T ABLE 3-16 describes the read-only Media Independent Interface (MII) capabilities.
48 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Reporting the Link Partner Capabilities T ABLE 3-17 describes the read-only link partner capabilities.
Chapter 3 Configuring Dr iver P arameters 49 If the link partner is not capable of autonegotiation (when lp-cap-autoneg is 0), the remaining information described in T ABLE 3-17 is not relevant and the parameter value is 0.
50 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 tx-queue3 Number of packets queued for transmission on the fourth hardwar e transmit queue. Unstable Ethernet Receive Counters rx-hdr-pkts Number of packets received that wer e less than 256 bytes.
Chapter 3 Configuring Dr iver P arameters 51 ▼ T o Check Link Partner Settings ● As superuser , type the kstat vca: N command: Note – In the previous example, N is the instance number of the vca device. This number should ref lect the instance number of the board for which you are running the kstat command.
52 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Network Conf iguration This section describes how to edit the network host files after the adapter has been installed on your system. Conf iguring the Network Host Files After installing the driver software, you must cr eate a hostname.
Chapter 3 Configuring Dr iver P arameters 53 T o use the vca interface of the example shown in Step 1, create an /etc/ hostname .vca N file, wher e N corresponds to the instance number of the device which is 0 in this example. If the instance number were 1, the file name would be /etc/ hostname .
54 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003.
55 CHAPTER 4 Administering the Sun Crypto Accelerator 4000 Boar d W ith the vcaadm and vcadiag Utilities This chapter provides an overview of the vcaadm and vcadiag utilities.
56 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 The vcaadm command-line syntax is: ■ vcaadm [-H] ■ vcaadm [-y] [-h host ] [-p port ] [-d vca N ] [-f filename ] .
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 57 Note – T o use vcaadm , you must authenticate as security officer . How often you need to authenticate as security officer is determined by which operating mode you are using.
58 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 T o enter commands in File mode, you specify a file from which vcaadm reads one or more commands. The f ile must be ASCII text, consisting of one command per line. Begin each comment with a pound sign (#) character .
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 59 Logging In to a Boar d W ith vcaadm If the security off icer connects to a new board, vcaadm wil.
60 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 When connecting to a new board, vcaadm must create a new entry in the tr ust database.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 61 vcaadm Prompt The vcaadm prompt in Interactive mode is displayed as follows: The following table.
62 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 In the previous example, notice the vcaadm> pr ompt no longer displays the device instance number , hostname, or security of ficer name. T o log in to another device, type the connect command with the following optional parameters.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 63 Entering Commands W ith vcaadm The vcaadm program has a command language that must be used to interact with the Sun Crypto Accelerator 4000 board.
64 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Getting Help for Commands vcaadm has built-in help functions. T o get help, you must enter a question mark (?) character following the command you want more help on.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 65 When not in vcaadm Interactive mode, the “?” character could be interpreted by the shell in which you are working. In this case, be sure to use the command shell escape character before the question mark.
66 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 ▼ T o Initialize the Su n Crypto Accelerator 4000 Boar d W ith a New Keystore 1.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 67 Note – Before an essential parameter is changed or deleted, or before a command is executed that may have drastic consequences, vcaadm prompts you to enter Y , Yes , N ,o r No to conf irm.
68 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 ▼ T o Initialize the Su n Crypto Accelerator 4000 Boar d to Use an Existing Keystore 1.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 69 Managing Keystor es W ith vcaadm A keystore is a r epository for key material. Associated with a keystore are security off icers and users. Keystores not only provide storage, but a means for key objects to be owned by user accounts.
70 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Setting the Password Requir ements Use the set passreq command to set the password r equirements for the Sun Crypto Accelerator 4000 board. This command sets the password character requir ements for any password prompted by vcaadm .
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 71 When creating a security of ficer , the name is an optional parameter on the command line. If the security off icer name is omitted, vcaadm will prompt you for the name.
72 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Note – The user account is logged out if no commands are entered for mor e than five minutes. This is a tunable option; see “Setting the Auto-Logout T ime” on page 76 for details.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 73 Enabling or Disabling Users Note – Security off icers cannot be disabled. Once a security officer is cr eated, it is enabled until it is deleted.
74 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Deleting Users Issue the delete user command and specify the user to be deleted. When deleting a user , the user name is an optional parameter on the command line. If the user name is omitted, vcaadm will prompt you for the user name.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 75 A password must be set for the backup data. This password is used to encrypt the master key that is in the backup file.
76 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Managing Boar ds W ith vcaadm This section describes how to manage Sun Crypto Accelerator 4000 boards with the vcaadm utility .
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 77 Displaying Boar d Status T o get the current status of a Sun Crypto Accelerator 4000 boar d, issue the show status command.
78 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Loading New Firmwar e It is possible to update the firmwar e for the Sun Crypto Accelerator 4000 board as new features ar e added. T o load firmware, issue the loadfw command and provide a path to the firmwar e file.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 79 Rekeying a Sun Crypto Accelerator 4000 Boar d Over time, it may be necessary because of your security policy to use new keys as the master key or remote access key .
80 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Zer oizing a Sun Crypto Accelerator 4000 Board In some situations, it might be necessary to clear a board of all its key material.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 81 bus, the DMA controller , and other hardware internals. T ests for the cryptographic subsystem cover random number generators and cryptographic accelerators.
82 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 T ABLE 4-1 shows the options for the vcadiag utility. The following is an example of the -D option: The following is an example of the -F option: T ABLE 4-7 vcadiag Options Option Meaning -D vca N Performs diagnostics on the Sun Crypto Accelerator 4000 boar d.
Chapter 4 Administering the Sun Cr ypto Accelerator 4000 Board With the vcaadm and vcadiag Utilities 83 The following is an example of the -K option: The following is an example of the -Q option: The .
84 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003.
85 CHAPTER 5 Conf iguring Sun ONE Server Softwar e for Use W ith the Sun Crypto Accelerator 4000 Boar d This chapter explains how to configure the Sun Crypto Accelerator 4000 board for use with Sun ONE W eb Servers.
86 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Concepts and T erminology Keystores and users must be cr eated for applications that communicate with the Sun Crypto Accelerator 4000 board through a PKCS#1 1 interface, such as the Sun ONE W eb Server .
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 87 T okens and T oken Files Keystores appear to Sun ONE W eb Servers as tokens . T oken f iles are a technique for Sun Crypto Accelerator 4000 administrators to selectively present only specific tokens to a given application.
88 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 The following is an example of the contents in a token file: Note – Comments are pr eceded by a pound sign (#) and empty lines are acceptable.
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 89 Conf iguring Sun ONE W eb Servers This section describes the following: ■ “Passwords” on pag.
90 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Populating a Keystor e Before you can enable the boar d for use with a Sun ONE W eb Server , you must first initialize the board and populate the board’s keystor e with at least one user .
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 91 4. Create a user with the create user command. The username and password created her e collectively make the username:password (See T ABLE 5-1 ). Y ou must use this password when authenticating during a web server startup.
92 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Installing and Conf iguring Sun ONE W eb Server 4.1 This section explains how to install and configure Sun ONE W eb Server 4.1. This chapter includes the following sections: ■ “Installing Sun ONE W eb Server 4.
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 93 ▼ T o Create a T rust Database 1. Start the Sun ONE W eb Server 4.1 Administration Server . Instead of running startconsole as setup requests, start a Sun ONE W eb Server 4.
94 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Note – If you want to run Secure Socket Layer (SSL) on the Sun ONE W eb Server 4.1 Administration Server server as well, the process of setting up a trust database is similar .
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 95 8. T ype y and press Return when prompted, if you want to proceed. 9. T ype 0 to quit. ▼ T o Generate a Server Certificate 1. Restart the Sun ONE W eb Server 4.
96 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 4. T o request the server certif icate, select the Security tab near the top of the Sun ONE W eb Server 4.1 Administration Server window ( FIGURE 5-1 ). The Create T rust Database page is displayed.
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 97 b. Select the Cryptographic Module you want to use. Each keystore has its own entry in this pull-down menu. Be sure that you select the correct keystor e.
98 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 ▼ T o Install the Server Certificate 1. Select the Install Certif icate link on the left side of the Sun ONE W eb Server 4.
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 99 4. Fill out the form to install your certif icate: 5. Paste the certif icate you copied from the certif icate authority (in Step 8 of the “T o Generate a Server Certif icate” on page 95) into the Message box.
100 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 4. Set encryption to On. The Port field in the dialog box should update to the default SSL port number 443. Alter the port number if necessary . 5. Select the OK button.
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 101 Note – The default server_port is 443. Installing and Conf iguring Sun ONE W eb Server 6.0 This section explains how to enable the Sun Crypto Accelerator 4000 board for use with Sun ONE 6.
102 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 c. Enter the Sun ONE W eb Server 6.0 Administration Server password twice. d. Press Return when prompted. ▼ T o Create a T rust Database 1. Start the Sun ONE W eb Server 6.
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 103 a. Select the Servers tab in the Sun ONE W eb Server 6.0 Administration Server window . b. Select a server and select the Manage button. c. Select the Security tab near the top of the page and select the Create Database link.
104 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 8. T ype y and press Return when prompted, if you want to proceed. 9.
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 105 4. T o request the server certif icate, select the Security tab near the top of Sun ONE W eb Server 6.0 Administration Server window . The Create T rust Database window is displayed.
106 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 b. Select the Cryptographic Module you want to use. Each keystore has its own entry in this pull-down menu. Be sure that you select the correct keystor e. Do not select SUNW acceleration only .
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 107 ▼ T o Install the Server Certificate 1. Select the Install Certif icate link on the left side of the Sun ONE W eb Server 6.0 Administration Server window .
108 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 4. Fill out the form to install your certif icate: 5. Paste the certif icate you copied from the certif icate authority (in Step 8 of the “T o Generate a Server Certif icate” on page 104) into the Message text box.
Chapter 5 Configuring Sun ONE Ser ver Softw are for Use With the Sun Crypto Accelerator 4000 Board 109 ■ Port : Set to the port on which you will be running your SSL-enabled web server (usually this is port 443). ■ Security : Set to On. b. Select the OK button to apply these changes.
110 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 At the Module keystore_name pr ompt, enter the username:password . Enter the username:password for other keystores as pr ompted. 12. V erify the new SSL-enabled web server at the following URL: https:// hostname.
111 CHAPTER 6 Conf iguring Apache W eb Servers for Use W ith the Sun Crypto Accelerator 4000 Boar d This chapter explains how to configure the Sun Crypto Accelerator 4000 board for use with Apache W eb Servers.
112 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Enabling the Boar d for Apache W eb Servers This section provides an overview of how to enable the Sun Crypto Accelerator 4000 board for use with Apache W eb Servers. Enabling Apache W eb Servers Apache W eb Server 1.
Chapter 6 Configuring Apache Web Servers f or Use With the Sun Cr ypto Accelerator 4000 Board 113 4. Select 1 to conf igure your Apache W eb Server to use SSL: 5. Provide the directory where the Apache binaries exist. On Solaris systems, this is usually /usr/apache .
114 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 9. Choose a base name for the key material. This name is appended with differ ent suffixes to distinguish key f iles, certificate request f iles and later on, certificate files fr om one another .
Chapter 6 Configuring Apache Web Servers f or Use With the Sun Cr ypto Accelerator 4000 Board 115 ▼ T o Create a Certif icate 1. Create a certif icate request using the keys you created in “T o Enable the Apache W eb Server” on page 1 12. Y ou must first enter the passwor d to access your keys.
116 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 2. Modify the /etc/apache/httpd.conf f ile as directed. Y ou are shown information concerning your key and certif icate files. Y ou are also instructed on how to modify the /etc/apache/httpd.
Chapter 6 Configuring Apache Web Servers f or Use With the Sun Cr ypto Accelerator 4000 Board 117 3. If you chose not to set up a VirtualHost , you must place the SSLEngine , SSLCertificateFile , and SSLCertificateKeyFile directives in the httpd.conf f ile, just above the SSLPassPhraseDialog directive.
118 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 5. Copy your certif icate request with the headers from /etc/apache/keys/ base_name -certreq.pem (where base_name was set in Step 9 of “T o Enable the Apache W eb Server” on page 1 12) and hand it off to your certif icate authority .
119 CHAPTER 7 Diagnostics and T r oubleshooting This chapter describes diagnostic tests and troubleshooting for the Sun Crypto Accelerator 4000 software.
120 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Installing SunVTS netlbtest and nettest Support for the vca Driver T ABLE 7-1 shows the method of updating installed SunVTS software to provide SunVTS netlbtest and nettest support for the vca driver .
Chapter 7 Diagnostics and T roubleshooting 121 Using the patchadd command to install patch 1 13614-1 1 is the equivalent of replacing the pr eviously installed SunVTS packages with the SunVTS5.1ps2 packages. The replacement packages ar e available at: http://www.
122 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Note – Physical mode is supported; however , this pr ocedure assumes you are using Logical mode.
Chapter 7 Diagnostics and T roubleshooting 123 T est Parameter Options for vcatest T ABLE 7-2 describes the vcatest subtests. vcatest Command-Line Syntax If you choose to perform vcatest from the command line instead of the CDE interface, then all arguments must be specified in the command-line string.
124 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 The following is an example of invoking vcatest in 64-bit mode from the SunVTS infrastructure.
Chapter 7 Diagnostics and T roubleshooting 125 5. Clear check boxes in the Network group that are not named vca N (netlbtest) . Note that N specif ies the placement of the instance number of the device under test. ■ If a vca N (netlbtest) is displayed, then go to Step 6.
126 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Refer to the SunVTS user ’s guide for detailed startup instructions. The following instructions assume that SunVTS was started using the CDE user interface. 2. On the SunVTS Diagnostic main window , set the System Map to Logical mode.
Chapter 7 Diagnostics and T roubleshooting 127 This action removes the dialog box and returns you to the SunVTS Diagnostic main window . 8. Select one of the instances of vca N (nettest) , then right-click and drag to display the T est Execution Options dialog box.
128 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Using kstat to Determine Cryptographic Activity The Sun Crypto Accelerator 4000 board does not contain lights or other indicators to ref lect cryptographic activity on the board.
Chapter 7 Diagnostics and T roubleshooting 129 Note – If the nostats property is def ined in the /kernel/drv/vca.conf file, the capture and display of statistics will be disabled.
130 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 3. Reset the system. 4. T ype show-nets to display the list of devices and enter a selection: Y ou should see a list .
Chapter 7 Diagnostics and T roubleshooting 131 Note – The Sun Crypto Accelerator 4000 UTP adapter self-test for a 1000 Mbps connection is not supported for use with an external loopback cable because the link-clock cannot be reconciled. For this test, the local and remote ports must reconcile as clock master and clock slave.
132 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 T r oubleshooting the Sun Crypto Accelerator 4000 Boar d This section describes the commands available at the OBP level for troubleshooting the board.
Chapter 7 Diagnostics and T roubleshooting 133 .properties T o determine whether the Sun Crypto Accelerator 4000 device properties ar e listed correctly: fr om the OBP prompt, type .
134 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 watch-net T o monitor a network connection: from the OBP prompt, type the apply watch- net command with the device path: The system monitors network traff ic, displaying “.
135 APPENDIX A Specif ications This appendix lists the specifications for the Sun Crypto Accelerator 4000 MMF and UTP adapters. It contains the following sections: ■ “Sun Crypto Accelerator 4000 M.
136 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 FIGURE A-1 Sun Crypto Accelerator 4000 MMF Adapter Connector T ABLE A-1 lists the characteristics of the SC connector (850 nm). T ABLE A-1 SC Connector Link Characteristics (IEEE P802.
Appendix A Specifications 137 Physical Dimensions Performance Specif ications Power Requir ements T ABLE A-2 Physical Dimensions Dimension Measurement Metric Measurement Length 12.
138 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Interface Specif ications Envir onmental Specifications Sun Crypto Accelerator 4000 UTP Adapter This section provides the specif ications for the Sun Crypto Accelerator 4000 UTP adapter .
Appendix A Specifications 139 FIGURE A-2 Sun Crypto Accelerator 4000 UTP Adapter Connector T ABLE A-7 lists the characteristics of the Cat-5 connector used by the Sun Crypto Accelerator 4000 UTP adapter .
140 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Physical Dimensions Performance Specif ications Power Requir ements T ABLE A-8 Physical Dimensions Dimension Measurement Metric Measurement Length 12.283 inches 312.00 mm W idth 4.
Appendix A Specifications 141 Interface Specif ications Envir onmental Specifications T ABLE A-11 Interface Specifications Feature Specification PCI clock 33 MHz or 66 MHz Host interface PCI 2.
142 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003.
143 APPENDIX B SSL Conf iguration Dir ectives for Apache W eb Servers This appendix lists directives for using Sun Crypto Accelerator 4000 software to configur e SSL support for Apache W eb Servers. Configure dir ectives in your http.conf file. Refer to the Apache W eb Server documentation for more information.
144 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 /etc/apache/ servername : port . keytype .pass . If this file is not pr esent, then the file /etc/apache/default.pass is used. These password f iles contain only the unencrypted password on a line by itself.
Appendix B SSL Configuration Directives f or Apache Web Servers 145 Using the plus (+) or minus (-) signs, protocols can be added or r emoved. For example, to disable support for SSLv2, the following directive could be used: The preceding statement is equivalent to: 4.
146 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 T ABLE B-3 lists and describes the aliases that provide macr o-like groupings.
Appendix B SSL Configuration Directives f or Apache Web Servers 147 The prefer ence of ciphers can be configured using the special characters listed and described in T ABLE B-4 .
148 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Certificates in the chain ar e assumed to be valid for client authentication as well, when client authentication ( SSLVerifyClient ) is used.
Appendix B SSL Configuration Directives f or Apache Web Servers 149 This directive specif ies a log file where SSL-specif ic information will be logged.
150 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Options are listed and described in T ABLE B-7 . 15. SSLRequireSSL Context: Directory , .htaccess This directive forbids access in a given dir ectory unless HTTPS is used.
151 APPENDIX C Building Applications for Use W ith the Sun Crypto Accelerator 4000 Boar d This appendix describes the software supplied with the Sun Crypto Accelerator 4000, which can be used to build OpenSSL-compatible applications to take advantage of the cryptographic acceleration features of the Sun Crypto Accelerator 4000 board.
152 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Additionally , the linker must be directed to include refer ences to the appropriate libraries. Most OpenSSL-compatible applications reference either or both of the libcrypto.
153 APPENDIX D Softwar e Licenses This appendix provides the Sun Binary Code License Agr eement and third-party software notices and licenses. Note – The third-party licenses and notices pr ovided in this appendix are included exactly as they are pr ovided by the owners of the software licenses and notices.
154 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 licensed or intended for use in the design, construction, operation or maintenance of any nuclear facility . Sun disclaims any express or implied warranty of fitness for such uses.
Appendix D Software Licenses 155 9. GOVERNING LA W . Any action related to this Agreement will be governed by California law and controlling U.S. federal law .
156 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Thir d Party License T erms OPENSSL LICENSE ISSUES The OpenSSL toolkit stays under a dual license, i.e. both the conditions of the OpenSSL License and the original SSLeay license apply to the toolkit.
Appendix D Software Licenses 157 OpenSSL PROJECT OR ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT , INDIRECT , INCIDENT AL, SPECIAL, EXEMPLARY , OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PR.
158 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 3. All advertising materials mentioning features or use of this softwar e must display the following acknowledgement: "This product includes cryptographic software written by Eric Y oung (eay@cryptsoft.
Appendix D Software Licenses 159 2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
160 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003.
161 APPENDIX E Manual Pages This appendix provides descriptions of the Sun Crypto Accelerator 4000 board commands and lists the online manual pages for each.
162 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 kcl2 (7d) The kcl2 device driver is a multithreaded loadable kernel module providing support for Sun cryptographic pr ovider drivers. The kcl2 driver requir es the presence of layer ed software for applications and kernel clients to access the provided services.
163 APPENDIX F Zer oizing the Har dwar e This appendix describes how to zeroize the Sun Crypto Accelerator 4000 boar d to the factory state which is the failsafe mode for the board. Caution – Y ou should use the procedures described in this appendix only if it is absolutely necessary .
164 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 ▼ T o Zer oize the Sun Crypto Accelerator 4000 Boar d W ith the Hardwar e Jumper 1.
Appendix F Zeroizing the Hardware 165 4. Power on the system. Caution – When you power on the system after adjusting the Sun Crypto Accelerator 4000 board jumper , all firmware, key material, and conf iguration information is deleted. This process returns the boar d to the factory state and places the board in failsafe mode.
166 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003.
167 APPENDIX G Fr equently Asked Questions How Do I Configur e the W eb Server to Startup W ithout User Interaction on Reboot? Y ou can enable both Sun ONE and Apache W eb Servers to perform an unattended startup at reboot with an encrypted key . ▼ T o Create an Encrypted Key for Automatic Startup of Apache W eb Servers on Reboot 1.
168 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 Example: For a server named webserv101 running SSL on port 443 with an RSA key , you create the following file in /et.
Appendix G Frequently Ask ed Questions 169 ▼ T o Assign Differ ent MAC Addresses Fr om a T erminal W indow 1. Enter the following command: Note – W ith the “ local-mac-address? ” parameter set to true , all nonintegrated network interface devices use the local MAC address assigned to the product at the manufacturing facility .
170 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 ■ For Sun Crypto Accelerator 1000 version 1.0 software – Patch ID 1 12869-02 ■ For Sun Crypto Accelerator 1000 version 1.1 software – Patch ID 1 13355-01 T o configur e the Sun Crypto Accelerator 1000 for use with Apache 1.
Index 171 Index SYMBOLS $HOME/.vcaadm/trustdb ,5 8 .properties command, 133 .u extension, 17 /etc/apache/default.pass , 144 /etc/apache/ servername.port.keytype.pass , 144 /etc/driver_aliases file, 38 /etc/hostname.vcaN file, 53 /etc/hosts file, 53 /etc/opt/SUNWconn/vca/keydata ,1 9 /etc/path_to_inst file, 38 /kernel/drv/vca.
172 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 SSLRequireSSL , 150 SSLVerifyClient , 148 SSLVerifyDepth , 148 enabling, 1 12 enabling the board, 1 12 applications, .
Index 173 enable-ipg0 ,2 8 enable-ipg0 parameter, 28 enabling Apache W eb Servers, 1 12 Sun ONE W eb Servers, 89 enabling Sun ONE W eb Servers, 91 etc/apache/default.
174 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 K kernel statistic values, 128 kernel/drv/vca.conf file, 129 key length, 1 14 key objects, 69 keystore data, 19 keystores, 66, 67, 86 managing with vcaadm ,6 9 kstat command, 43, 51, 128 L libcrypto.
Index 175 P packages optional, 17 requir ed, 17 parallel-detection, 42 parameter values how to modify and display, 34 parameters, 25 8-bit vectors, 30 adv-asmpause-cap ,2 7 adv-autoneg-cap ,2 4 adv-pa.
176 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 requir ed patches, 10 RSA keypair, 1 13 RX blanking register for alias r ead, 30 RX MAC counters, 45 RX random early .
Index 177 software, 10 Solaris operating environments, 10 SSL algorithms, 4 T token files, 87 tokens, 87 transmit and receive pause capability, 27 transmit counters, 49 transmit MAC counters, 45 troubleshooting, 132 trust database creating Sun ONE Web Server 4.
178 Sun Crypto Accelerator 4000 Board Installation and User’s Guide • May 2003 W watch-net command, 134 Z zeroize command, 163 zeroizing the har dware, 163.
Un punto importante, dopo l’acquisto del dispositivo (o anche prima di acquisto) è quello di leggere il manuale. Dobbiamo farlo per diversi motivi semplici:
Se non hai ancora comprato il Sun Microsystems 4000 è un buon momento per familiarizzare con i dati di base del prodotto. Prime consultare le pagine iniziali del manuale d’uso, che si trova al di sopra. Dovresti trovare lì i dati tecnici più importanti del Sun Microsystems 4000 - in questo modo è possibile verificare se l’apparecchio soddisfa le tue esigenze. Esplorando le pagine segenti del manuali d’uso Sun Microsystems 4000 imparerai tutte le caratteristiche del prodotto e le informazioni sul suo funzionamento. Le informazioni sul Sun Microsystems 4000 ti aiuteranno sicuramente a prendere una decisione relativa all’acquisto.
In una situazione in cui hai già il Sun Microsystems 4000, ma non hai ancora letto il manuale d’uso, dovresti farlo per le ragioni sopra descritte. Saprai quindi se hai correttamente usato le funzioni disponibili, e se hai commesso errori che possono ridurre la durata di vita del Sun Microsystems 4000.
Tuttavia, uno dei ruoli più importanti per l’utente svolti dal manuale d’uso è quello di aiutare a risolvere i problemi con il Sun Microsystems 4000. Quasi sempre, ci troverai Troubleshooting, cioè i guasti più frequenti e malfunzionamenti del dispositivo Sun Microsystems 4000 insieme con le istruzioni su come risolverli. Anche se non si riesci a risolvere il problema, il manuale d’uso ti mostrerà il percorso di ulteriori procedimenti – il contatto con il centro servizio clienti o il servizio più vicino.