Case Ii: Security Databases To Hsm Migration - Red Hat CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE:
Table of Contents

Advertisement

Server-Cert cert-old_TKS_instance cu,cu,cu
caSigningCert cert-old_TKS_instance CT,c,
tksTransportCert cert-old_TKS_instance CT,C,
9.
Open the CS.cfg configuration file.
cd /var/lib/instance_ID/conf/
vi CS.cfg
10. If server-side keygen has been enabled, edit the tks.drm_transport_cert_nickname attribute to reflect the
new TKS instance.
tks.drm_transport_cert_nickname=
tksTransportCert cert-old_TKS_instance
11. If a master key was migrated from an old TKS instance, edit the new Certificate System CS.cfg, and insert the
"tks.mk_mappings.#tks_master_key_version_number#01=internal:tks_master_key_version_name" value
from the old Certificate System CS.cfg file. Be sure to use the proper tks_master_key_version_number and
tks_master_key_version_name values.
NOTE
The caSigningCert is not referenced in the CS.cfg file.
12. In the same directory, edit the serverCertNick.conf file to contain the old certificate nickname. For example:
vi serverCertNick.conf
Server-Cert cert-old_TKS_instance

6.4.2. Case II: Security Databases to HSM Migration

1.
Remove all the security databases in the new Certificate System which will receive migrated data.
rm /var/lib/instance_ID/alias/cert8.db
rm /var/lib/instance_ID/alias/key3.db
2.
Log into the old server as the Certificate System user for that machine.
3.
To migrate a master key from the old TKS instance, do the following:
a.
Open the configuration file for the old server instance being migrated.
If the migration is from Certificate Management System 7.0, this configuration file is the CMS.cfg in the old
Certificate System config/ directory. If the migration is from Certificate System 7.1, this file is CS.cfg in
the old server config/ directory.
b.
Write down or note the exact value for the tks.mk_mappings. line, which has the following format.
tks.mk_mappings.#tks_master_key_version_number
#01=internal:tks_master_key_version_name
A tks.mk_mappings value looks like the following example:
tks.mk_mappings.#02#01=internal:tks_master_key_v2
6.4. 7.0 and 7.1 Token Key Service
(TKS) Migration
Databases

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE and is the answer not in the manual?

Questions and answers

Table of Contents