HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 120

Downloading the local CA certificate, Creating and installing the SKM server certificate

Page 120 highlights

3 Steps for connecting to an SKM appliance Repeat these steps any time another local CA is needed. Downloading the local CA certificate The local CA certificate you created using the procedure for "Setting up the local Certificate Authority (CA)" on page 100 must be saved to your local system. Later, this certificate must be imported onto the Brocade encryption group leader nodes. 1. From the Security tab, select Local CAs under Certificates and CAs. 2. Select the CA certificate you created. 3. Click Download, and save the certificate file on your local system. 4. Rename the downloaded file, changing the .cert extension to a .pem extension. This file is needed later when "Registering SKM on a Brocade encryption group leader" on page 109. Creating and installing the SKM server certificate To create the SKM server certificate, perform the following steps: 1. Click the Security tab. 2. Under Certificates and CAs, select Certificates. 3. Enter the required information under Create Certificate Request. - Enter a Certificate Name and Common Name. The same name may be used for both. - Enter your organizational information. - Enter the E-mail Address where you want messages to the Security Officer to go. - Enter the Key Size. HP recommends using the default value: 1024. 4. Click Create Certificate Request. Successful completion is indicated when the new entry for the server certificate appears on the Certificate List with a Certificate Status of Request Pending. 5. Select the newly created server certificate from the Certificate List. 6. Select Properties. The pending request displays under Certificate Request Information. 7. Copy the certificate data from -----BEGIN CERTIFICATE REQUEST----- to -----END CERTIFICATE REQUEST----- lines. Be careful to exclude extra carriage returns or spaces after the data. 8. Under Certificates & CAs, select Local CAs. The Certificate and CA Configuration page is displayed. 9. From the CA Name column, select the local CA name you created in . 10. Click Sign Request. 102 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

102
Fabric OS Encryption Administrator’s Guide
53-1001864-01
Steps for connecting to an SKM appliance
3
Repeat these steps any time another local CA is needed.
Downloading the local CA certificate
The local CA certificate you created using the procedure for
“Setting up the local Certificate
Authority (CA)”
on page 100 must be saved to your local system. Later, this certificate must be
imported onto the Brocade encryption group leader nodes.
1.
From the
Security
tab, select
Local CAs
under
Certificates and CAs
.
2.
Select the CA certificate you created.
3.
Click
Download
, and save the certificate file on your local system.
4.
Rename the downloaded file, changing the .cert extension to a .pem extension. This file is
needed later when
“Registering SKM on a Brocade encryption group leader”
on page 109.
Creating and installing the SKM server certificate
To create the SKM server certificate, perform the following steps:
1.
Click the
Security
tab.
2.
Under
Certificates and CAs
, select
Certificates
.
3.
Enter the required information under
Create Certificate Request
.
-
Enter a
Certificate Name
and
Common Name
. The same name may be used for both.
-
Enter your organizational information.
-
Enter the
E-mail Address
where you want messages to the Security Officer to go.
-
Enter the
Key Size
. HP recommends using the default value: 1024.
4.
Click
Create Certificate Request
.
Successful completion is indicated when the new entry for the server certificate appears on
the
Certificate List
with a
Certificate Status
of
Request Pending.
5.
Select the newly created server certificate from the
Certificate List
.
6.
Select
Properties
.
The pending request displays under
Certificate Request Information
.
7.
Copy the certificate data from -----BEGIN CERTIFICATE REQUEST----- to -----END CERTIFICATE
REQUEST--––– lines. Be careful to exclude extra carriage returns or spaces after the data.
8.
Under
Certificates & CAs
, select
Local CAs
.
The
Certificate and CA Configuration
page is displayed.
9.
From the
CA Name
column, select the local CA name you created in .
10. Click
Sign Request
.