beautypg.com

Establishing a cluster, Establishing a, Cluster – HP Secure Key Manager User Manual

Page 37

background image

11.

Click Sign Request.

12.

Copy the signed certificate data, from -----BEGIN to END…----- lines. Be careful to exclude

extra carriage returns or spaces after the data. This information will be used in step 16 of this section.

13.

In the Certificates & CAs menu, click on Certificates.

14.

Click on the certificate name created in steps 3 – 4 of this section. For example, SKM Server.

15.

Click Install Certificate.

16.

Paste the signed certificate data from step 12 and click Save. Note that the Certificate status is

now Active.

Enabling SSL on the Key Management System (KMS) Server

The KMS Server provides the interface to the client. Secure Sockets Layer (SSL) must be enabled on the

KMS Server before this interface will operate. After SSL is enabled on the first appliance it will be

automatically enabled on the other cluster members.
To configure and enable SSL, perform the following steps:

1.

Select the Device tab.

2.

In the Device Configuration menu, click KMS Server to display the Key Management Services

Configuration window.

3.

In the KMS Server Settings section of the window, click Edit. The following warning may display.

4.

Configure the KMS Server Settings as shown. (Ensure that the port and connection timeout settings

are 9000 and 3600, respectively). For Server Certificate, select the name of the certificate you

created in

Creating the SKM server certificate

, step 4. For example, SKM Server.

5.

Click Save.

IMPORTANT:

Please apply the most recent security patch(es) to ensure maximum security.
Receive support alerts, driver updates, software, firmware, and customer replaceable components, in

your E-mail through HP Subscriber’s Choice. Sign up for Subscriber’s Choice Driver, Patch, Security, and

Support alerts at the following URL:

http://www.hp.com/go/myadvisory

Establishing a cluster

The procedures in this section will establish a cluster configuration on one SKM appliance and then

transfer that configuration to the remaining appliances.

Secure Key Manager

37