HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 122

Creating an SKM High Availability cluster, Copying the local CA certificate

Page 122 highlights

3 Steps for connecting to an SKM appliance Creating an SKM High Availability cluster The HP SKM key vault supports clustering of HP SKM appliances for high availability. If two SKM key vaults are configured, they must be clustered. If only a single SKM appliance is configured, it may be clustered for backup purposes, but the backup appliance will not be directly used by the switch. The procedures in this section will establish a cluster configuration on one SKM appliance and then transfer that configuration to the remaining appliances. • Create the cluster on one SKM appliance that is to be a member of the cluster. • Copy the local CA certificate from the first SKM appliance or an existing cluster member. • Paste the local CA certificate it into the management console for each of the SKM appliances added to the cluster. To create a cluster, perform the following steps on one of the HP SKM appliances that is to be a member of the cluster. 1. From the SKM management console, click the Device tab. 2. In the Device Configuration menu, click Cluster. The Create Cluster section displays. 3. Select and note the Local IP address. You will need this address when you add an appliance to the cluster. 4. For Local Port, use the default value of 9001 unless you are explicitly directed to use a different value for your site. 5. Type the cluster password in the Create Cluster section of the main window to create the new cluster. 6. Click the Create button. 7. In the Cluster Settings section of the window, click Download Cluster Key and save the key to a convenient location, such as your computer's desktop. The cluster key is a text file and is only required temporarily. It may be deleted from your computer's desktop after all SKM appliances have been added to the cluster. Copying the local CA certificate Before adding an SKM appliance to a cluster, you must obtain the local CA certificate from the original SKM or from an SKM that is already in the cluster. 1. Select the Security tab. 2. Select Local CAs under Certificates & CAs. 3. Select the name of the local CA from the Local Certificate Authority list. The CA Certificate Information is displayed. 4. Copy the certificate request, beginning with ---BEGIN CERTIFICATE REQUEST--- and ending with ---END CERTIFICATE REQUEST---. Be careful not to include any extra characters. 104 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

104
Fabric OS Encryption Administrator’s Guide
53-1001864-01
Steps for connecting to an SKM appliance
3
Creating an SKM High Availability cluster
The HP SKM key vault supports clustering of HP SKM appliances for high availability. If two SKM
key vaults are configured, they must be clustered. If only a single SKM appliance is configured, it
may be clustered for backup purposes, but the backup appliance will not be directly used by the
switch. The procedures in this section will establish a cluster configuration on one SKM appliance
and then transfer that configuration to the remaining appliances.
Create the cluster on one SKM appliance that is to be a member of the cluster.
Copy the local CA certificate from the first SKM appliance or an existing cluster member.
Paste the local CA certificate it into the management console for each of the SKM appliances
added to the cluster.
To create a cluster, perform the following steps on one of the HP SKM appliances that is to be a
member of the cluster.
1.
From the SKM management console, click the
Device
tab.
2.
In the
Device Configuration
menu, click
Cluster
.
The
Create Cluster
section displays.
3.
Select and note the
Local IP
address. You will need this address when you add an appliance to
the cluster.
4.
For
Local Port
, use the default value of 9001 unless you are explicitly directed to use a
different value for your site.
5.
Type the cluster password in the
Create Cluster
section of the main window to create the new
cluster.
6.
Click the
Create
button.
7.
In the
Cluster Settings
section of the window, click
Download Cluster Key
and save the key to a
convenient location, such as your computer's desktop. The cluster key is a text file and is only
required temporarily. It may be deleted from your computer's desktop after all SKM appliances
have been added to the cluster.
Copying the local CA certificate
Before adding an SKM appliance to a cluster, you must obtain the local CA certificate from the
original SKM or from an SKM that is already in the cluster.
1.
Select the
Security
tab.
2.
Select
Local CAs
under
Certificates & CAs
.
3.
Select the name of the local CA from the
Local Certificate Authority
list.
The
CA Certificate Information
is displayed.
4.
Copy the certificate request, beginning with
---BEGIN CERTIFICATE REQUEST---
and ending
with
---END CERTIFICATE REQUEST---
. Be careful not to include any extra characters.