< Home

Agile Controller Server Authentication Security

Overview

Huawei Agile Controller is a system for automatic network resource control specific to users and applications. Following the centralized control principle of SDN, the Agile Controller dynamically schedules network resources to make networks agile for services. It uses XMPP to communicate and manage the device. The Agile Controller and device implement security hardening measures from the following aspects during their communication.

The device and the Agile Controller server use a shared key to exchange authentication messages. In Agile Controller authentication, the device record logs in detail on the messages sent by the server for auditing and source tracing.

For security reasons, you are advised to change the default shared key promptly. The new key must contain characters in at least three of the following types of characters: lower-case letters, upper-case letters, digits, and special characters.

Impact on the System

None

Procedure

  1. After a shared key is configured, the device saves the shared key in ciphertext to prevent key disclosure.

    <HUAWEI> system-view 
    [HUAWEI] tsm-server template test
    [HUAWEI-tsm-test] tsm-server encryption-mode aes128 shared-key Admin@1234

Checking the Security Hardening Result

Run the display tsm-server template command to check whether the configuration of the Agile Controller server template is correct.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic