HP Brocade 8/12c Fabric OS Encryption Administrator's Guide - Page 54

Signing the Brocade encryption node KAC certificates, Public Key Certificate Request CSR

Page 54 highlights

2 Steps for connecting to an SKM or ESKM appliance Enter information required in the Install CA Certificate section near the bottom of the page. - Enter the Certificate Name of the certificate being transferred from the first cluster member. - Paste the copied certificate data into the Certificate box. 4. Click Install. 5. In the Certificates & CA menu, click Trusted CA Lists. 6. Click on the Default Profile Name. 7. Click Edit. 8. Select the name of the CA from the list of Available CAs in the right panel. 9. Click Add. 10. Click Save. 11. Select the Device tab. 12. In the Device Configuration menu, click Cluster. 13. Click Join Cluster. In the Join Cluster section of the window, leave Local IP and Local Port set to their default settings. 14. Enter the original cluster member's local IP address into Cluster Member IP. 15. Enter the original cluster member's local Port into Cluster Member Port. 16. Click Browse, then select the Cluster Key File you saved. 17. Enter the cluster password into Cluster Password. 18. Click Join. 19. After adding all members to the cluster, delete the cluster key file from the desktop. 20. Create and install an SKM/ESKM server certificate. Refer to "Creating and installing the SKM or ESKM server certificate" on page 30 for a description of this procedure. Signing the Brocade encryption node KAC certificates The KAC certificate signing request generated when the encryption node is initialized must be exported for each encryption node and signed by the Brocade local CA on SKM/ESKM. The signed certificate must then be imported back into the encryption node. 1. Select Configure > Encryption from the menu task bar. The Encryption Center dialog box displays. 2. Select a switch from the Encryption Center Devices table, then select Switch > Export Certificate, from the menu task bar, or right-click a switch and select Export Certificate. The Export Switch Certificate dialog box displays. 3. Select Public Key Certificate Request (CSR), then click OK. You are prompted to save the CSR, which can be saved to your SAN Management Program client PC, or an external host of your choosing. 34 Fabric OS Encryption Administrator's Guide 53-1002159-03

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282

34
Fabric OS Encryption Administrator’s Guide
53-1002159-03
Steps for connecting to an SKM or ESKM appliance
2
Enter information required in the Install CA Certificate section near the bottom of the page.
-
Enter the
Certificate Name
of the certificate being transferred from the first cluster
member.
-
Paste the copied certificate data into the
Certificate
box.
4.
Click
Install
.
5.
In the
Certificates & CA
menu, click
Trusted CA Lists
.
6.
Click on the
Default Profile Name
.
7.
Click
Edit
.
8.
Select the name of the CA from the list of
Available CAs
in the right panel.
9.
Click
Add
.
10. Click
Save
.
11.
Select the
Device
tab.
12.
In the
Device Configuration
menu, click
Cluster
.
13. Click
Join Cluster
. In the
Join Cluster
section of the window, leave
Local IP
and
Local Port
set to
their default settings.
14.
Enter the original cluster member’s local IP address into
Cluster Member IP
.
15.
Enter the original cluster member’s local Port into
Cluster Member Port
.
16. Click
Browse
, then select the
Cluster Key File
you saved.
17.
Enter the cluster password into
Cluster Password
.
18. Click
Join
.
19.
After adding all members to the cluster, delete the cluster key file from the desktop.
20.
Create and install an SKM/ESKM server certificate. Refer to
“Creating and installing the SKM
or ESKM server certificate”
on page 30 for a description of this procedure.
Signing the Brocade encryption node KAC certificates
The KAC certificate signing request generated when the encryption node is initialized must be
exported for each encryption node and signed by the Brocade local CA on SKM/ESKM. The signed
certificate must then be imported back into the encryption node.
1.
Select
Configure > Encryption
from the menu task bar.
The
Encryption Center
dialog box displays.
2.
Select a switch from the
Encryption Center Devices
table, then select
Switch > Export
Certificate
, from the menu task bar, or right-click a switch and select
Export Certificate
.
The
Export Switch Certificate
dialog box displays.
3.
Select
Public Key Certificate Request (CSR)
, then click
OK
.
You are prompted to save the CSR, which can be saved to your SAN Management Program
client PC, or an external host of your choosing.