HP MSA 1040 HP MSA 1040 SMU Reference Guide (762784-001, March 2014) - Page 165

Installing a security certificate

Page 165 highlights

Installing a security certificate The storage system supports use of unique certificates for secure data communications, to authenticate that the expected storage systems are being managed. Use of authentication certificates applies to the HTTPS protocol, which is used by the web server in each controller module. As an alternative to using the CLI to create a security certificate on the storage system, you can use FTP to install a custom certificate on the system. A certificate consists of a certificate file and an associated key file. The certificate can be created by using OpenSSL, for example, and is expected to be valid. If you replace the controller module in which a custom certificate is installed, the partner controller will automatically install the certificate file to the replacement controller module. To install a security certificate 1. In SMU, prepare to use FTP: a. Determine the network-port IP addresses of the system's controllers; see "Changing network interface settings" (page 48). b. Verify that the system's FTP service is enabled; see "Changing management interface settings" (page 40). c. Verify that the user you will log in as has permission to use the FTP interface; see "Modifying users" (page 44). 2. Open a Command Prompt (Windows) or a terminal window (UNIX) and navigate to the directory that contains the certificate files. 3. Enter: ftp controller-network-address For example: ftp 10.1.0.9 4. Log in as a user that has permission to use the FTP interface. 5. Enter: put certificate-file-name cert-file where certificate-file-name is the name of the certificate file for your specific system. 6. Enter: put key-file-name cert-key-file where key-file-name is the name of the security key file for your specific system. 7. Restart both Management Controllers to have the new security certificate take effect. Installing a security certificate 165

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190

Installing a security certificate
165
Installing a security certificate
The storage system supports use of unique certificates for secure data communications, to authenticate that the
expected storage systems are being managed. Use of authentication certificates applies to the HTTPS protocol, which
is used by the web server in each controller module.
As an alternative to using the CLI to create a security certificate on the storage system, you can use FTP to install a
custom certificate on the system. A certificate consists of a certificate file and an associated key file. The certificate
can be created by using OpenSSL, for example, and is expected to be valid. If you replace the controller module in
which a custom certificate is installed, the partner controller will automatically install the certificate file to the
replacement controller module.
To install a security certificate
1.
In SMU, prepare to use FTP:
a.
Determine the network-port IP addresses of the system’s controllers; see
"Changing network interface settings"
(page 48)
.
b.
Verify that the system’s FTP service is enabled; see
"Changing management interface settings" (page 40)
.
c.
Verify that the user you will log in as has permission to use the FTP interface; see
"Modifying users"
(page 44)
.
2.
Open a Command Prompt (Windows) or a terminal window (UNIX) and navigate to the directory that contains
the certificate files.
3.
Enter:
ftp
controller-network-address
For example:
ftp 10.1.0.9
4.
Log in as a user that has permission to use the FTP interface.
5.
Enter:
put
certificate-file-name
cert-file
where
certificate-file-name
is the name of the certificate file for your specific system.
6.
Enter:
put
key-file-name
cert-key-file
where
key-file-name
is the name of the security key file for your specific system.
7.
Restart both Management Controllers to have the new security certificate take effect.