Signing The Encryption Node Kac Csr On Eskm/Skm - Brocade Communications Systems StoreFabric SN6500B User Manual

Brocade network advisor san user manual v12.0.0 (53-1002696-01, march 2013)
Hide thumbs Also See for StoreFabric SN6500B:
Table of Contents

Advertisement

20
Steps for connecting to an ESKM/SKM appliance
9. Click Save.
10. Select the Device tab.
11. In the Device Configuration menu, click Cluster.
12. Click Join Cluster. In the Join Cluster section of the window, leave Local IP and Local Port set to
13. Enter the original cluster member's local IP address into Cluster Member IP.
14. Enter the original cluster member's local Port into Cluster Member Port.
15. Click Browse, then select the Cluster Key File you saved.
16. Enter the cluster password, then click Join.
17. After adding all members to the cluster, delete the cluster key file from the desktop.
18. Create and install an ESKM/SKM server certificate. Refer to

Signing the encryption node KAC CSR on ESKM/SKM

The KAC certificate signing request generated when the encryption node is initialized must be
exported for each encryption node and signed by the Brocade local CA on ESKM/SKM. The signed
certificate must then be imported back into the encryption node.
1. Select Configure > Encryption from the menu task bar to display the The Encryption Center
2. Select a switch from the Encryption Center Devices table, then select Switch > Export
3. Select Public Key Certificate Request (CSR), then click OK.
4. Launch the ESKM/SKM administration console in a web browser and log in.
5. Select the Security tab.
6. Select Local CAs under Certificates & CAs.
7.
8. Select Sign Request.
9. Select Sign with Certificate Authority using the Brocade CA name and maximum of 3649 days.
10. Select Client as Certificate Purpose.
11. Allow Certificate Duration to default to 3649.
562
their default settings.
ESKM/SKM server certificate"
dialog box (Refer to
Figure 185
Certificate, from the menu task bar.
The Export Switch Certificate dialog box displays.
You are prompted to save the CSR, which can be saved to your SAN Management Program
client PC, or an external host of your choosing.
Alternatively, you may select a switch, then select Switch > Properties. Click the Export button
beside the Public Key Certificate Request, or copy the CSR for pasting into the Certificate
Request Copy area on the ESKM/SKM Sign Certificate Request page.
The Certificate and CA Configuration page displays.
Under Local Certificate Authority List, select the Brocade CA name.
The Sign Certificate Request page displays.
on page 559 for a description of this procedure.
on page 526).
"Creating and installing the
Brocade Network Advisor SAN User Manual
53-1002696-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Brocade network advisor 12.0.0

Table of Contents