Novell ACCESS MANAGER 3.1 SP1 - IDENTITY SERVER Manual page 54

Identity server guide
Table of Contents

Advertisement

C:\nfast\bin>net stop "nfast server"
C:\nfast\bin>net start "nfast server"
8 Configure communication to the remote file system server. In this sample configuration, the
remote file system is installed on a Windows machine.
8a At the remote file system server, enable communication with the Identity Server. For a
Windows machine, enter the following command:
C:\nfast\bin\rfs-setup.exe --gang-client --write-noauth <address>
Replace <address> with the IP address of the Identity Server.
8b At the Identity Server, enable communication with the remote file system server. For
nCipher, enter the following command:
Linux:
Windows:
Replace <address> with the IP address of the remote file system server.
8c At the Identity Server, initialize synchronization with the remote file system server.
Linux: Enter the following commands:
/opt/nfast/bin/rfs-sync –-update
/opt/nfast/bin/rfs-sync –-commit
Windows: Enter the following commands:
C:\nfast\bin>rfs-sync --update
C:\nfast\bin>rfs-sync --commit
The first command reads updates from the remote file system server and downloads files
to the
C:\nfast\kmdata\local
changes to the remote file system server.
9 Continue with
Creating the nCipher Signing Key Pair
IMPORTANT: Because of Access Manager configuration conflicts, you need to use a netHSM
client other than the Identity Server. The remote file system server is a netHSM client, or if you have
configured another device as a client, you can use that device.
The following commands are specific to nCipher; it does not come with a tool to generate a key pair
and CSR. nCipher also uses a unique keystore of type
nCipher supports both a Windows and a Linux netHSM client.
If you have a Windows netHSM client, the command is located in the following directory:
c:\Program Files\Java\jdk1.5.0_14\jre\bin\java
If you have Linux netHSM client, the command is located in the following directory:
/opt/novell/java/bin/java
54
Novell Access Manager 3.1 SP1 Identity Server Guide
/opt/nfast/bin/rfs-sync --setup --no-authenticate <address>
C:\nfast\bin>rfs-sync --setup --no-authenticate <address>
/opt/nfast/kmdata/local
directory on Windows. The second command writes local
"Creating the nCipher Signing Key Pair" on page
directory on Linux and the
54.
nCipher.sworld
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Access manager 3.1 sp1

Table of Contents