Configuring Media Servers and Clients
Oracle Secure Backup creates security credentials for a host when you use the Oracle
Secure Backup
Web tool
The procedure differs depending on whether you add hosts in automated or
certificate provisioning
"Determining the Distribution Method of Host Identity
See Also:
Certificates"
on page 6-7
Automated Certificate Provisioning Mode
If you create the hosts in
required to perform additional steps. Oracle Secure Backup creates the wallet, keys,
and certificates for the host automatically as part of the normal host configuration.
Manual Certificate Provisioning Mode
You must use the obcm utility when you add hosts in the domain in manual rather
than
automated certificate provisioning
does not issue a signed certificate to a host over the network, so you must export the
signed certificate from the
the newly configured host, and then import the certificate into the host's wallet.
Both an
identity certificate
operating system user running obcm must have write permissions in the wallet
directory. By default, the wallet used by Oracle Secure Backup is located in the
following locations:
/usr/etc/ob/wallet (UNIX and Linux)
■
C:\Program Files\Oracle\Backup\db\wallet (Windows)
■
The obcm utility always accesses the wallet in the preceding locations. You cannot
override the default location.
If you choose to add hosts in
perform the following steps for each host:
Log on to the administrative server.
1.
Assuming that your PATH variable is set correctly, enter obcm at the operating
2.
system command line to start the obcm utility. The operating system user running
obcm must have write permissions in the wallet directory.
Enter the following command, where hostname is the name of the host
3.
requesting the certificate and certificate_file is the filename of the exported
request:
export --certificate --file certificate_file --host hostname
For example, the following command exports the signed certificate for host
brhost2 to file /tmp/brhost2_cert.f:
export --certificate --file /tmp/brhost2_cert.f --host brhost2
Copy the signed identity certificate to some type of physical media and physically
4.
transfer the media to the host.
Log on to the host whose wallet contains the certificate.
5.
Assuming that your PATH variable is set correctly, enter obcm at the operating
6.
system command line to start the obcm utility. The operating system user running
obcm must have write permissions in the wallet directory.
Configuring Security for the Administrative Domain
or run the mkhost command in
mode.
automated certificate provisioning
mode. In this case, the certificate authority
administrative
server, manually transfer the certificate to
and a wallet exist as files on the operating system. The
manual certificate provisioning
Managing Security for Backup Networks 6-17
obtool
to configure the host.
manual
mode, then you are not
mode, then you must
Need help?
Do you have a question about the Secure Backup and is the answer not in the manual?
Questions and answers