Steps For Connecting To An Eskm/Skm Appliance - Brocade Communications Systems WFT-2D User Manual

San user manual
Table of Contents

Advertisement

LKM/SSKM key vault deregistration
Deregistration of either the primary or secondary LKM/SSKM key vault from an encryption switch
or blade is allowed independently.

Steps for connecting to an ESKM/SKM appliance

The ESKM/SKM management web console can be accessed from any web browser with Internet
access to the ESKM/SKM appliance. The URL for the appliance is as follows:
Where:
The following configuration steps are performed from the ESKM/SKM management web console
and from the Management application:
Brocade Network Advisor SAN User Manual
53-1003154-01
Deregistration of Primary LKM/SSKM: You can deregister the Primary LKM/SSKM from an
encryption switch or blade without deregistering the backup or secondary LKM/SSKM for
maintenance or replacement purposes. However, when the primary LKM/SSKM is
deregistered, key creation operations will fail until either the primary LKM/SSKM is
reregistered, or the secondary LKM/SSKM is deregistered and reregistered as the primary
LKM/SSKM.
When the primary LKM/SSKM is replaced with a different LKM/SSKM, you must first
synchronize the DEKs from the secondary LKM/SSKM before reregistering the primary
LKM/SSKM.
Deregistration of Secondary LKM/SSKM: You can deregister the secondary LKM/SSKM
independently. Future key operations will use only the primary LKM/SSKM until the secondary
LKM/SSKM is reregistered on the encryption switch or blade.
When the secondary LKM/SSKM is replaced with a different LKM/SSKM, you must first
synchronize the DEKs from the primary LKM/SSKM before reregistering the secondary
LKM/SSKM.
https://<appliance hostname>:<appliance port number>
-
<appliance hostname>
appliance.
-
<appliance port number>
when installing the ESKM/SKM appliance, use that port number.
Configure a Brocade group on the ESKM/SKM. Refer to
ESKM/SKM"
on page 724.
Register the Brocade group user name and password on the encryption node. Refer to
"Registering the ESKM/SKM Brocade group user name and password"
Set up a local CA on the ESKM/SKM. Refer to
ESKM/SKM"
on page 726.
Download the CA certificate. Refer to
on page 727.
Create and install an ESKM/SKM server certificate. Refer to
ESKM/SKM server certificate"
Steps for connecting to an ESKM/SKM appliance
is the hostname or IP address when installing the ESKM/SKM
is 9443 by default. If a different port number was specified
"Setting up the local Certificate Authority (CA) on
"Downloading the local CA certificate from ESKM/SKM"
on page 727.
"Configuring a Brocade group on
on page 725.
"Creating and installing the
20
723

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network advisor 12.3.0

Table of Contents