HP Cisco MDS 9216A Cisco MDS 9000 Family Storage Media Encryption Configuratio - Page 251
Use JAVA keytool JRE 1.6 to generate Java keystores.
View all HP Cisco MDS 9216A manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 251 highlights
Appendix C Provisioning Self-Sign Certificates Generating and Installing Self-Signed Certificates Send documentation comments to [email protected] a Generate all certificates and configure switch h Print this usage screen switch:./createSmeCerts.tcl a Dir to store certificates [] :. Openssl path [/usr/bin] : RootCA CN [RootCA] :SMECA Trust Pass Phrase [nbv123] :nbv123 Certificate Validity days [365] :1024 Trust point name [sme_ca] : Generating CA certificate ... Generated CA certificate /users/filename1/SSL script/./cacert.pem Create switch certificate and configure trustpoint ... Switch IP [] :switchname username [] :admin password [] : Created certificate and configured trustpoint for switch: ips-hac4 Do you want to configure another switch? (y/n) [n] :n Generating KMC certificate ... KMC Common Name [] :KMC Generated KMC certificate: /users/filename1/SSL script/./sme_KMC_server.p12 switch:./createSmeCerts.tcl k Dir where RootCA certificate is stored [] :. Reading properties from /users/filename1/SSL script/./sme_cert.properties Generating KMC certificate ... KMC Common Name [] :FM Generated KMC certificate: /users/filename1/SSL script/./sme_FM_server.p12 switch:ls cacert.pem cacert.srl createSmeCerts.tcl* createSmeCerts.tcl.orig* openssl.conf switch: openssl_FM.conf openssl_KMC.conf privkey.pem README* sme_cert.properties sme_FM_server.cert sme_FM_server.csr sme_FM_server.key sme_FM_server.p12 sme_KMC_server.cert sme_KMC_server.csr sme_KMC_server.key sme_KMC_server.p12 sw_ips.csr sw_ips.pem Step 2 Use JAVA keytool (JRE 1.6) to generate Java keystores. "C:\Program Files\Java\jre1.6.0_02\bin\keytool.exe" -importkeystore -srckeystore sme_KMC_server.p12 -srcstoretype PKCS12 -destkeystore sme_kmc_server.jks -deststoretype JKS "C:\Program Files\Java\jre1.6.0_02\bin\keytool.exe" -importkeystore -srckeystore sme_FM_server.p12 -srcstoretype PKCS12 -destkeystore sme_fm_server.jks -deststoretype JKS "C:\Program Files\Java\jre1.6.0_02\bin\keytool.exe" -importcert -file cacert.pem -keystore sme_kmc_trust.jks -storetype JKS "C:\Program Files\Java\jre1.6.0_02\bin\keytool.exe" -importcert -file cacert.pem -keystore fmtrust.jks -storetype JKS Step 3 Run the following commands for the Fabric Manager server: Copy sme_fm_server.jks to /jboss/server/default/conf/fmserver.jks Copy fmtrust.jks to /jboss/server/default/conf/fmtrust.jks Go to /bin OL-18091-01, Cisco MDS NX-OS Release 4.x Cisco MDS 9000 Family Storage Media Encryption Configuration Guide C-5