Enabling Ssl On The Key Management System; (Kms) Server - Brocade Communications Systems 1606 Administrator's Manual

Fabric os encryption administrator's guide v6.4.0 (53-1001864-01, june 2010)
Hide thumbs Also See for 1606:
Table of Contents

Advertisement

11. Enter the required data in the Sign Certificate Request section of the window.
12. Paste the copied certificate request data into the Certificate Request box.
13. Click Sign Request.
14. Click Download to download the signed certificate to your local system.
15. Copy the signed certificate data, from -----BEGIN to END...----- lines. Be careful to exclude extra
16. From the Security tab select Certificates under Certificates & CAs.
17. Select the server certificate name you just created from the certificate list, and select
18. Click Install Certificate.
19. Paste the signed certificate data you copied under Certificate Response and click Save.
Enabling SSL on the Key Management System (KMS) Server
The KMS Server provides the interface to the client. Secure Sockets Layer (SSL) must be enabled
on the KMS Server before this interface will operate. After SSL is enabled on the first appliance it
will be automatically enabled on the other cluster members.
To configure and enable SSL, perform the following steps:
1. Select the Device tab.
2. In the Device Configuration menu, click KMS Server to display the Key Management Services
3. In the KMS Server Settings section of the window, click Edit. The following warning may display.
4. Configure the KMS Server Settings. Ensure that the port and connection timeout settings are
5. Click Save.
Fabric OS Encryption Administrator's Guide
53-1001864-01
-
Select the CA name from the Sign with Certificate Authority drop down box.
-
Select Server as the Certificate Purpose.
-
Enter the number of days before the certificate must be renewed based on your site's
security policies. The default value is 3649 or 10 years.
The signed certificate request data displays under Sign Certificate Request.
carriage returns or spaces after the data.
Properties.
The Certificate Request Information window displays.
The Certificate Installation window displays.
The status of the server certificate should change from Request Pending to Active.
Configuration window.
9000 and 3600, respectively. For Server Certificate, select the name of the certificate you
created in
"Creating and installing the SKM server certificate"
Steps for connecting to an SKM appliance
on page 28.
2
29

Advertisement

Table of Contents
loading

Table of Contents