Creating A Self-Signed Certificate For Tklm; Importing The Fabric Os Encryption Node Kac Certificates To Tklm; Exporting The Tklm Self-Signed Server Certificate - Brocade Communications Systems Brocade 8/12c User Manual

Brocade network advisor san user manual v11.1x (53-1002167-01, may 2011)
Hide thumbs Also See for Brocade 8/12c:
Table of Contents

Advertisement

Creating a self-signed certificate for TKLM

You must create a self-signed certificate for TKLM that can be downloaded to the Fabric OS
encryption engines to verify the authenticity of TKLM.
1. Select Tivoli Key Lifecycle Manager > Configuration.
2. Select Create self-signed certificate.
3. Under Certificate label in key store, enter a certificate label.
4. Under Certificate description (common name), enter a descriptive name.
5. Under Validity period of new certificate, enter the desired life time for the certificate.
6. Select Tivoli Key Lifecycle Manager > Advanced Configuration > Server Certificates to verify
7.

Importing the Fabric OS encryption node KAC certificates to TKLM

The KAC certificates previously exported from the Fabric OS encryption nodes to an external LINUX
host must now be imported into the TKLM server file system. You must import the KAC certificate in
.der format. To do this, refer to
1. Import the KAC certificate from the external host into the TKLM server file system using a
2. Select Tivoli Key Lifecycle Manager > Advanced Configuration > Client Certificates.
3. Select Import > SSL Certificate.
4. Enter the Fabric OS KAC certificate name in the Certificate field.
5. Under File name and location, enter or browse to the location where the imported KAC
6. Select Trust.
7.
8. Verify that the imported certificate is valid and active.

Exporting the TKLM self-signed server certificate

The TKLM self-signed server certificate must be exported in preparation for importing and
registering the certificate on a Fabric OS encryption group leader node.
1. Enter the TKLM server wsadmin CLI.
Brocade Network Advisor SAN User Manual
53-1002167-01
The Configuration page displays.
that the certificate label is listed on Administer Server Certificates under Certificates.
Reboot the TKLM server.
binary file transfer mechanism using FTP, USB, or SCP.
The Client Certificates page displays.
The Import SSL/KMIP Certificates for Clients page displays.
certificate is stored.
Select Import.
For Linux (in ./wsadmin.sh):
<installed directory>/IBM/tivoli/tiptklmV2/bin/wsadmin.sh -username TKLMAdmin
-password <password> -lang jython
Steps for connecting to a TKLM appliance
"Converting the KAC certificate format"
18
on page 470.
471

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network advisor 11.1.xBrocade bladesystem 4/24

Table of Contents