HP Integrity rx2800 Installation Guide, Windows Server 2008 R2 v7.0 - Page 88

Securing the WBEM Connection, Managing nPartitions Using WBEM, WBEM SSL Certificate cert.pem file

Page 88 highlights

data in a consistent fashion. Client applications can then use this information to manage an enterprise computing environment. Because WBEM supports a distributed management architecture, client applications (nPartition management tools, for example) can run on a remote system and use the WBEM infrastructure to send requests to managed servers. Partition Manager is a WBEM client application. Partition Manager uses WBEM when retrieving information about a server complex. Partition Manager uses nPartition commands for all other operations. The nPartition commands are also WBEM client applications. Several software components support nPartition commands for Windows. The Windows OS provides the Windows Management Instrumentation (WMI) software, which is an implementation of WBEM standards. HP provides a WMI-based nPartition Provider and WMI mapper to convert CIM/XML WBEM requests from clients (like nPartition commands and Partition Manager) into WMI requests. The nPartition commands and Partition Manager send management messages to the nPartition Provider. The nPartition Provider handles communication with the MP using the IPMI protocol, locally through an IPMI/BT device driver, or remotely using the MP IPMI/LAN interface. Securing the WBEM Connection WBEM secures the management connection using an SSL authentication process, which involves the following files: • WBEM SSL Certificate (cert.pem file) The WBEM SSL certificate file resides on the system that is being managed and contains the local WBEM server's certificate. On a Windows system, the WBEM SSL certificate file is in the location specified by the sslCertificateFilePath entry in the %PEGASUS_HOME%\cimserver_current.conf file, and is usually %SystemDrive%\hp\sslshare\cert.pem. • WBEM Trusted Certificate Store (known_hosts.pem file) The WBEM Trusted Certificate Store file resides on the system from which you issue WBEM remote management commands. On a Windows system, the WBEM Trusted Certificate Store file resides in the %SystemDrive%\hp\sslshare directory. • Partition Manager Trusted Certificate Store (parmgr.keystore file) The Partition Manager Certificate Store file resides on the system from which you run Partition Manager. Partition Manager uses it to validate server certificates. On a Windows system, the Partition Manager Trusted Certificate Store file resides in the %SystemDrive%\hp\sslshare directory. For remote WBEM SSL connections to succeed, the WBEM SSL server certificate from the remote system you are connecting to (the WBEM server) must be imported into the trusted certificate stores on the system where the remote WBEM commands are issued from (the client system). Managing nPartitions Using WBEM Using WBEM, you can manage remote nPartitions indirectly, through an nPartition on the server. NOTE: You cannot use WBEM to manage nPartitions remotely if none of the nPartitions on the target server have been booted or configured yet, or if the nPartition provider or MP device driver components have not been installed yet. To use WBEM, install the WMI Mapper and the nPartition commands software on your management station. After you install the tools, enable secure WBEM communications. Then you can use Partition Manager or nPartition commands to manage the remote nPartitions. 88 nPartitioning

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110

data in a consistent fashion. Client applications can then use this information to manage an
enterprise computing environment.
Because WBEM supports a distributed management architecture, client applications (nPartition
management tools, for example) can run on a remote system and use the WBEM infrastructure
to send requests to managed servers.
Partition Manager is a WBEM client application. Partition Manager uses WBEM when retrieving
information about a server complex. Partition Manager uses nPartition commands for all other
operations. The nPartition commands are also WBEM client applications.
Several software components support nPartition commands for Windows. The Windows OS
provides the Windows Management Instrumentation (WMI) software, which is an implementation
of WBEM standards. HP provides a WMI-based nPartition Provider and WMI mapper to convert
CIM/XML WBEM requests from clients (like nPartition commands and Partition Manager) into
WMI requests.
The nPartition commands and Partition Manager send management messages to the nPartition
Provider. The nPartition Provider handles communication with the MP using the IPMI protocol,
locally through an IPMI/BT device driver, or remotely using the MP IPMI/LAN interface.
Securing the WBEM Connection
WBEM secures the management connection using an SSL authentication process, which involves
the following files:
WBEM SSL Certificate (cert.pem file)
The WBEM SSL certificate file resides on the system
that is being managed and contains the local WBEM server’s certificate.
On a Windows system, the WBEM SSL certificate file is in the location specified by the
sslCertificateFilePath entry in the
%PEGASUS_HOME%\cimserver_current.conf
file,
and is usually
%SystemDrive%\hp\sslshare\cert.pem
.
WBEM Trusted Certificate Store (known_hosts.pem file)
The WBEM Trusted Certificate Store
file resides on the system from which you issue WBEM remote management commands.
On a Windows system, the WBEM Trusted Certificate Store file resides in the
%SystemDrive%\hp\sslshare
directory.
Partition Manager Trusted Certificate Store (parmgr.keystore file)
The Partition Manager
Certificate Store file resides on the system from which you run Partition Manager. Partition
Manager uses it to validate server certificates. On a Windows system, the Partition Manager
Trusted Certificate Store file resides in the
%SystemDrive%\hp\sslshare
directory.
For remote WBEM SSL connections to succeed, the WBEM SSL server certificate from the remote
system you are connecting to (the WBEM server) must be imported into the trusted certificate
stores on the system where the remote WBEM commands are issued from (the client system).
Managing nPartitions Using WBEM
Using WBEM, you can manage remote nPartitions indirectly, through an nPartition on the server.
NOTE:
You
cannot
use WBEM to manage nPartitions remotely if none of the nPartitions on the
target server have been booted or configured yet, or if the nPartition provider or MP device
driver components have not been installed yet.
To use WBEM, install the WMI Mapper and the nPartition commands software on your
management station. After you install the tools, enable secure WBEM communications. Then
you can use Partition Manager or nPartition commands to manage the remote nPartitions.
88
nPartitioning