7b To restart the nfast client:
Linux: Enter the following command:
/opt/nfast/sbin/init.d-nfast restart
Windows: Enter the following commands:
C:\nfast\bin>net stop "nfast server"
C:\nfast\bin>net start "nfast server"
8 Configure communication to the remote file system server. In this sample configuration, the
remote file system is installed on a Windows machine.
8a At the remote file system server, enable communication with the Identity Server. For a
Windows machine, enter the following command:
C:\nfast\bin\rfs-setup.exe --gang-client --write-noauth <address>
Replace <address> with the IP address of the Identity Server.
8b At the Identity Server, enable communication with the remote file system server. For
nCipher, enter the following command:
Linux:
Windows:
Replace <address> with the IP address of the remote file system server.
8c At the Identity Server, initialize synchronization with the remote file system server.
Linux: Enter the following commands:
/opt/nfast/bin/rfs-sync –-update
/opt/nfast/bin/rfs-sync –-commit
Windows: Enter the following commands:
C:\nfast\bin>rfs-sync --update
C:\nfast\bin>rfs-sync --commit
The first command reads updates from the remote file system server and downloads files
to the
C:\nfast\kmdata\local
changes to the remote file system server.
9 Continue with
Creating the nCipher Signing Key Pair
IMPORTANT: Because of Access Manager configuration conflicts, you need to use a netHSM
client other than the Identity Server. The remote file system server is a netHSM client, or if you have
configured another device as a client, you can use that device.
The following commands are specific to nCipher; it does not come with a tool to generate a key pair
and CSR. nCipher also uses a unique keystore of type
nCipher supports both a Windows and a Linux netHSM client.
If you have a Windows netHSM client, the command is located in the following directory:
c:\Program Files\Java\jdk1.5.0_14\jre\bin\java
46
Novell Access Manager 3.1 SP2 Identity Server Guide
/opt/nfast/bin/rfs-sync --setup --no-authenticate <address>
C:\nfast\bin>rfs-sync --setup --no-authenticate <address>
/opt/nfast/kmdata/local
directory on Windows. The second command writes local
"Creating the nCipher Signing Key Pair" on page
directory on Linux and the
46.
nCipher.sworld
.
Need help?
Do you have a question about the ACCESS MANAGER 3.1 SP2 - IDENTITY SERVER GUIDE 2010 and is the answer not in the manual?
Questions and answers