3 At the netHSM server, configure the server to allow the Identity Server to be a client.
Check your netHSM documentation for the specific steps.
4 (Conditional) If your Identity Server cluster configuration contains more than one Identity
Server, configure the netHSM server to allow the other Identity Servers in the cluster to be a
client.
5 At the Identity Server, enroll the client to use the server:
5a To get the ESN and hash numbers for the enroll command, enter the following command:
Linux:
/opt/nfast/bin/anonkneti <IP_address>
Windows:
C:\nfast\bin>anonkneti <IP_address>
Replace <IP_address> with the IP address of the netHSM server.
5b To enroll the client, enter the following command:
Linux:
/opt/nfast/bin/nethsmenroll -p <IP_address> <ESN> <hash>
Windows:
C:\nfast\bin>nethsmenroll -p <IP_address> <ESN> <hash>
Replace <IP_address> with the IP address of the netHSM server. Replace <ESN> and
<hash> with the values copied from the
6 (Conditional) If the Identity Server and the Administration Console are installed on the same
machine, modify the 9000 and 9001 TCP ports:
6a In a text editor, open the
Linux:
/opt/novell/devman/share/conf
Windows Server 2003:
INF\conf
Windows Server 2008:
WEB-INF\conf
6b Change the ports from 9000 and 9001 to another value, such as 9010 and 9011.
The lines should look similar to the following:
<stringParam name="ExecutorPort" value="9010" />
<stringParam name="SchedulerPort" value="9011" />
6c Save the changes.
6d Restart Tomcat:
Linux: Enter the following command:
/etc/init.d/novell-tomcat5 restart
Windows: Enter the following commands:
net stop Tomcat5
net start Tomcat5
6e (Conditional) If other Identity Servers in the cluster contain an Administration Console,
repeat
Step
6.
7 At the Identity Server, enable the netHSM client so that it uses TCP:
7a Enter the following command:
Linux:
/opt/nfast/bin/config-serverstartup -sp
Windows:
C:\nfast\bin>config-serverstartup -sp
anonkneti
file located in the following directory:
sc.conf
\Program Files\Novell\Tomcat\webapps\roma\WEB-
\Program Files (x86)\Novell\Tomcat\webapps\roma\
command.
Configuring an Identity Server
45
Need help?
Do you have a question about the ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 and is the answer not in the manual?
Questions and answers