McAfee MEJCAE-AM-DA Product Guide - Page 41

Reconstituting a split key over the network, Joining a key over the network

Page 41 highlights

Managing Keys Splitting and rejoining a key 5 Enter a new passphrase for the key. 6 Enter the new passphrase again for confirmation. Reconstituting a split key over the network To reconstitute a split key over the network, you use the --key-join option. Once you have created a split key, you must send the shares to the shareholders in other locations. You can do this by ftp or via email. You must have a signing key on your keyring to set up a TLS connection, which provides a secure link to transmit the key shares securely to individuals in other locations. This key is authenticated by the remote machine to establish its trust of your identity. Likewise, the remote machine presents its key so that you can authenticate the identity of the remote user. You must establish mutual validity for these keys. You can specify the signing key you want to use for the TLS connection using the --auth-user option, or you can let E-Business Server choose a signing key on your keyring for you. Joining a key over the network To join a key over the network, you must perform actions on the system that contains the split key and on each remote system. On the system that contains the split key 1 Enter the following at the command line: ebs --key-join [--auth-user ] 2 Press Enter. 3 E-Business Server chooses a signing key on your keyring to set up a TLS connection (unless you specified a key with --auth-user). 4 Enter the passphrase for this key. 5 The system opens a TLS connection and waits to receive the shares. The system displays, "Listening..." At each remote site: 1 Enter the following on the command line: ebs --send-shares [--auth-user ] 2 Enter the IP address for the remote system. 3 Enter your passphrase to decrypt the share. The system displays, "Preparing to send the key share." E-Business Server chooses a signing key on your keyring to authenticate the TLS connection (unless you specified a key with --auth-user). 4 Enter the passphrase for this key. 5 When prompted, type Y to confirm the connection. On the system that contains the split key 1 When prompted, type Y to confirm the connection. Once the connection is confirmed on both ends, the share is sent securely over the network and received by the system containing the split key. When the minimum number of shares needed to rejoin the key is received, then the key is rejoined. 2 Enter a new passphrase for the key. 39 E-Business Server™ 8.6 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188

39
E-Business Server
8.6
Product Guide
Managing Keys
Splitting and rejoining a key
5
Enter a new passphrase for the key.
6
Enter the new passphrase again for confirmation.
Reconstituting a split key over the network
To reconstitute a split key over the network, you use the
--key-join
option. Once you have created a split
key, you must send the shares to the shareholders in other locations. You can do this by ftp or via email.
You must have a signing key on your keyring to set up a TLS connection, which provides a secure link to
transmit the key shares securely to individuals in other locations. This key is authenticated by the remote
machine to establish its trust of your identity. Likewise, the remote machine presents its key so that you can
authenticate the identity of the remote user. You must establish mutual validity for these keys.
You can specify the signing key you want to use for the TLS connection using the
--auth-user
option, or you
can let E-Business Server choose a signing key on your keyring for you.
Joining a key over the network
To join a key over the network, you must perform actions on the system that contains the split key
and
on
each remote system.
On the system that contains the split key
1
Enter the following at the command line:
ebs --key-join <userID of key to join> [--auth-user <userID>]
2
Press
Enter
.
3
E-Business Server chooses a signing key on your keyring to set up a TLS connection (unless you specified
a key with
--auth-user
).
4
Enter the passphrase for this key.
5
The system opens a TLS connection and waits to receive the shares.
The system displays, “
Listening...
At each remote site:
1
Enter the following on the command line:
ebs --send-shares <quoted_share_filename> [--auth-user <userID>]
2
Enter the IP address for the remote system.
3
Enter your passphrase to decrypt the share.
The system displays, “
Preparing to send the key share.
E-Business Server chooses a signing key on your keyring to authenticate the TLS connection (unless
you specified a key with
--auth-user
).
4
Enter the passphrase for this key.
5
When prompted, type
Y
to confirm the connection.
On the system that contains the split key
1
When prompted, type
Y
to confirm the connection.
Once the connection is confirmed on both ends, the share is sent securely over the network and received by
the system containing the split key. When the minimum number of shares needed to rejoin the key is
received, then the key is rejoined.
2
Enter a new passphrase for the key.