Preparing To Install A Redundant Peer - Acopia ARX 1000 Hardware Installation Manual

Adaptive resourse switch
Table of Contents

Advertisement

Preparing to Install a Redundant Peer

Applying the Master Key
...
The master key is used to encrypt critical security parameters.
15. Enter the master key
in the format base64-encoded key or keyword 'generate'.(default=generate) #
2oftVCwAAAAgAAAApwazSRFd2ww/H1pi7R7JMDZ9SoIg4WGA/XsZP+HcXjsIAAAADDRbMCxE/bc=
The wrapping password is used to encrypt and decrypt the master key.
16. Enter the wrapping password
ARX®1000 Hardware Installation Guide
The initial-boot script requires some additional information if you are
installing the second switch in a redundant pair. Both members of a
redundant pair share a common master key. A master key is an encryption
key for all critical-security parameters (CSPs), such as administrative
passwords. Redundant switches share the same users, groups, and
passwords, so they must use the same master key.
At the peer that is currently installed, use the
create an encrypted copy of the master key:
show master-key
The CLI prompts you for two passwords:
System Password
is a password entered at initial-boot time (see Sample:
Booting a Non-Replacement Switch, on page 6-4). It is 12-32 characters
long. This validates that you have permission to access the master key.
Wrapping Password
is set with this command. The security software uses
this to encrypt (and later decrypt) the master-key string.
Enter 12-32 characters. At least one character in this password must be a
number (0-9) or a symbol (!, @, #, $, and so on).
Save this password: you will need it to decrypt the master key later, on
the new switch.
This command outputs a base64-encoded string that is the encrypted master
key. Save this string and the wrapping password that you set in the
command.
For example, this shows the master key on a switch named "prtlndA1kB:"
prtlndA1kB# show master-key
Master Key System Password: %uper$ecretpw
Wrapping Password: an0ther$ecretpw
Validate Wrapping Password: an0ther$ecretpw
Encrypted master key:
2oftVCwAAAAgAAAApwazSRFd2ww/H1pi7R7JMDZ9SoIg4WGA/XsZP+HcXjsIAAA
ADDRbMCxE/bc=
prtlndA1kB# ...
As shown earlier, there is a prompt for the master key in the initial-boot
script. You can answer this prompt with the encrypted master key; the script
then prompts for the wrapping password. For example,
Booting the Switch
show master-key
command to
6 - 9

Advertisement

Table of Contents
loading

Table of Contents